CVE-2024-22366(yamaha / wlx202)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Active debug code exists in Yamaha wireless LAN access point devices. If a logged-in user who knows how to use the debug function accesses the device's management page, this function can be enabled by performing specific operations. As a result, an arbitrary OS command may be executed and/or configuration settings of the device may be altered. Affected products and versions are as follows: WLX222 firmware Rev.24.00.03 and earlier, WLX413 firmware Rev.22.00.05 and earlier, WLX212 firmware Rev.21.00.12 and earlier, WLX313 firmware Rev.18.00.12 and earlier, and WLX202 firmware Rev.16.00.18 and earlier.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wlx202
  • wlx202_firmware
  • wlx212
  • wlx212_firmware

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Vendors
Products
wlx202wlx202_firmwarewlx212wlx212_firmwarewlx222wlx222_firmwarewlx313wlx313_firmwarewlx413wlx413_firmware

1 version affected across 10 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-02: 110-02
Referenced assets4 URLs
Full discourse1 post
  • yousukezan@yousukezan

    Yamahaのルータは最近脆弱性の公開はないですがVPNと無線LANアクセスポイントの脆弱性がありますね UTM UTX200 / UTX100 のVPN(2026年、CVE-2026-50751 / 50752、CVE-2026-85102 / 85103) 認証回避による不正VPN接続、サイト間VPNの中間者攻撃、任意プログラム実行の可能性。ルーターおよびファイアウォールは影響を受けない。 https://www.rtpro.yamaha.co.jp/RT/FAQ/Security/CVE-2026-50751.html https://www.rtpro.yamaha.co.jp/RT/FAQ/Security/CVE-2026-85102.html 無線LANアクセスポイント WLX(2024-01-23、JVNVU#99896362、CVE-2024-22366) 有効化できるデバッグ機能。ログイン後の特定操作で任意OSコマンドや設定変更の可能性。WLX202 / 212 / 222 / 313 / 413。ルーター本体は非該当。 https://jvn.jp/vu/JVNVU99896362/ https://www.rtpro.yamaha.co.jp/RT/FAQ/Security/JVNVU99896362.html

    0511843.7K
    15.9K followersView on X
CPE platform detail10 entries

10 of 10 entries

PartVendorProductVersionTarget SWTarget HW
HWyamahawlx202---
OSyamahawlx202_firmware---
HWyamahawlx212---
OSyamahawlx212_firmware---
HWyamahawlx222---
OSyamahawlx222_firmware---
HWyamahawlx313---
OSyamahawlx313_firmware---
HWyamahawlx413---
OSyamahawlx413_firmware---

Explore more