CVE-2023-49038
Published Jan 29, 2024Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as root.
Vendor/product archive
2 CVEs tagged to buffalo / ls210d_firmware — 0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.
Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as root.
An issue in Buffalo LS210D v.1.78-0.03 allows a remote attacker to execute arbitrary code via the Firmware Update Script at /etc/init.d/update_notifications.sh.