Buffalo kayıtları
buffalo üreticisine ait 61 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %1,6
- Silahlaştırılmış
- 1 · %1,6
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- 188 gün
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-306 Missing Authentication for Critical Function3
- CWE-287 Improper Authentication3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
61 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
99Hemen | CVE-2021-20090Silahlaştırılmış | A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= buffalo · wsr-2533dhpl2-bk firmware · CWE-22 | Kritik9,8 | KEV | %100,0 | 29 Nis 2021 |
46Planlayın | CVE-2018-13324İstismar yok | Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified buffalo · ts5600d1206 firmware · CWE-863 | Kritik9,8 | — | %23,2 | 26 Kas 2018 |
40Planlayın | CVE-2017-2126İstismar yok | WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication andbuffalo · wapm-1166d firmware · CWE-287 | Kritik9,8 | — | %4,0 | 21 Tem 2017 |
40Planlayın | CVE-2021-20716İstismar yok | Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 buffalo · bhr-4rv firmware | Kritik9,8 | — | %3,2 | 27 Nis 2021 |
39İzleyin | CVE-2018-16988İstismar yok | An issue was discovered in Open XDMoD through 7.5.0.buffalo · open xdmod · CWE-640 | Kritik9,8 | — | %1,6 | 2 May 2019 |
39İzleyin | CVE-2024-23486İstismar yok | Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wibuffalo · wsr-2533dhp firmware · CWE-256 | Kritik9,8 | — | %0,6 | 15 Nis 2024 |
38İzleyin | CVE-2021-20091Kavram kanıtı | The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize userbuffalo · wsr-2533dhpl2-bk firmware | Yüksek8,8 | — | %8,8 | 29 Nis 2021 |
37İzleyin | CVE-2026-45779İstismar yok | Open XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Database Compromisebuffalo · open xdmod · CWE-89 | Kritik9,3 | — | %0,9 | 5 Haz 2026 |
37İzleyin | CVE-2026-45777İstismar yok | Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command Injectionbuffalo · open xdmod · CWE-78 | Kritik9,3 | — | %0,7 | 5 Haz 2026 |
35İzleyin | CVE-2018-13321İstismar yok | Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal functions via the "mbuffalo · ts5600d1206 firmware · CWE-732 | Yüksek8,8 | — | %1,0 | 26 Kas 2018 |
35İzleyin | CVE-2021-3512İstismar yok | Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 anbuffalo · bhr-4grv firmware | Yüksek8,8 | — | %0,9 | 27 Nis 2021 |
35İzleyin | CVE-2018-0554İstismar yok | Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspebuffalo · wzr-1750dhp2 firmware · CWE-306 | Yüksek8,8 | — | %0,8 | 9 Nis 2018 |
35İzleyin | CVE-2018-0521İstismar yok | Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device buffalo · wxr-1900dhp2 firmware · CWE-306 | Yüksek8,8 | — | %0,8 | 9 Mar 2018 |
35İzleyin | CVE-2022-43443İstismar yok | OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a spbuffalo · wsr-3200ax4s firmware · CWE-78 | Yüksek8,8 | — | %0,8 | 18 Ara 2022 |
35İzleyin | CVE-2017-2273İstismar yok | Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remobuffalo · wmr-433 firmware · CWE-352 | Yüksek8,8 | — | %0,8 | 21 Tem 2017 |
35İzleyin | CVE-2018-0556İstismar yok | Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.buffalo · wzr-1750dhp2 firmware · CWE-78 | Yüksek8,8 | — | %0,7 | 9 Nis 2018 |
35İzleyin | CVE-2018-0523İstismar yok | Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.buffalo · wxr-1900dhp2 firmware · CWE-78 | Yüksek8,8 | — | %0,7 | 9 Mar 2018 |
35İzleyin | CVE-2021-20731İstismar yok | WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands witbuffalo · wsr-1166dhp4 firmware · CWE-78 | Yüksek8,8 | — | %0,6 | 8 Haz 2021 |
35İzleyin | CVE-2022-40966İstismar yok | Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and accebuffalo · wcr-300 firmware · CWE-287 | Yüksek8,8 | — | %0,4 | 7 Ara 2022 |
34İzleyin | CVE-2026-27650İstismar yok | OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products.buffalo · wcr-1166dhpl firmware · CWE-78 | Yüksek8,6 | — | %1,4 | 27 Mar 2026 |
34İzleyin | CVE-2026-33280İstismar yok | Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging fubuffalo · wcr-1166dhpl firmware · CWE-912 | Yüksek8,6 | — | %0,7 | 27 Mar 2026 |
34İzleyin | CVE-2026-32678İstismar yok | Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings wibuffalo · wzr-s900dhp firmware · CWE-288 | Yüksek8,7 | — | %0,5 | 27 Mar 2026 |
34İzleyin | CVE-2026-32669İstismar yok | Code injection vulnerability exists in BUFFALO Wi-Fi router products.buffalo · wcr-1166dhpl firmware · CWE-94 | Yüksek8,7 | — | %0,5 | 27 Mar 2026 |
34İzleyin | CVE-2026-45778İstismar yok | Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Resetbuffalo · open xdmod · CWE-79 | Yüksek8,6 | — | %0,2 | 5 Haz 2026 |
32İzleyin | CVE-2021-20092Kavram kanıtı | The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict accebuffalo · wsr-2533dhpl2-bk firmware · CWE-287 | Yüksek7,5 | — | %8,2 | 29 Nis 2021 |
- CVE-2021-2009099Hemen
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <=
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100buffalo · wsr-2533dhpl2-bk firmware29 Nis 2021
- CVE-2018-1332446Planlayın
Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified
KritikCVSS 9,8İstismar yokEPSS %23buffalo · ts5600d1206 firmware26 Kas 2018
- CVE-2017-212640Planlayın
WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and
KritikCVSS 9,8İstismar yokEPSS %4buffalo · wapm-1166d firmware21 Tem 2017
- CVE-2021-2071640Planlayın
Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11
KritikCVSS 9,8İstismar yokEPSS %3buffalo · bhr-4rv firmware27 Nis 2021
- CVE-2018-1698839İzleyin
An issue was discovered in Open XDMoD through 7.5.0.
KritikCVSS 9,8İstismar yokEPSS %2buffalo · open xdmod2 May 2019
- CVE-2024-2348639İzleyin
Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wi
KritikCVSS 9,8İstismar yokEPSS %1buffalo · wsr-2533dhp firmware15 Nis 2024
- CVE-2021-2009138İzleyin
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user
YüksekCVSS 8,8Kavram kanıtıEPSS %9buffalo · wsr-2533dhpl2-bk firmware29 Nis 2021
- CVE-2026-4577937İzleyin
Open XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Database Compromise
KritikCVSS 9,3İstismar yokEPSS %1buffalo · open xdmod5 Haz 2026
- CVE-2026-4577737İzleyin
Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command Injection
KritikCVSS 9,3İstismar yokEPSS %1buffalo · open xdmod5 Haz 2026
- CVE-2018-1332135İzleyin
Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal functions via the "m
YüksekCVSS 8,8İstismar yokEPSS %1buffalo · ts5600d1206 firmware26 Kas 2018
- CVE-2021-351235İzleyin
Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 an
YüksekCVSS 8,8İstismar yokEPSS %1buffalo · bhr-4grv firmware27 Nis 2021
- CVE-2018-055435İzleyin
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspe
YüksekCVSS 8,8İstismar yokEPSS %1buffalo · wzr-1750dhp2 firmware9 Nis 2018
- CVE-2018-052135İzleyin
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device
YüksekCVSS 8,8İstismar yokEPSS %1buffalo · wxr-1900dhp2 firmware9 Mar 2018
- CVE-2022-4344335İzleyin
OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a sp
YüksekCVSS 8,8İstismar yokEPSS %1buffalo · wsr-3200ax4s firmware18 Ara 2022
- CVE-2017-227335İzleyin
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remo
YüksekCVSS 8,8İstismar yokEPSS %1buffalo · wmr-433 firmware21 Tem 2017
- CVE-2018-055635İzleyin
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
YüksekCVSS 8,8İstismar yokEPSS %1buffalo · wzr-1750dhp2 firmware9 Nis 2018
- CVE-2018-052335İzleyin
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
YüksekCVSS 8,8İstismar yokEPSS %1buffalo · wxr-1900dhp2 firmware9 Mar 2018
- CVE-2021-2073135İzleyin
WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands wit
YüksekCVSS 8,8İstismar yokEPSS %1buffalo · wsr-1166dhp4 firmware8 Haz 2021
- CVE-2022-4096635İzleyin
Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and acce
YüksekCVSS 8,8İstismar yokEPSS %0buffalo · wcr-300 firmware7 Ara 2022
- CVE-2026-2765034İzleyin
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products.
YüksekCVSS 8,6İstismar yokEPSS %1buffalo · wcr-1166dhpl firmware27 Mar 2026
- CVE-2026-3328034İzleyin
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging fu
YüksekCVSS 8,6İstismar yokEPSS %1buffalo · wcr-1166dhpl firmware27 Mar 2026
- CVE-2026-3267834İzleyin
Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings wi
YüksekCVSS 8,7İstismar yokEPSS %1buffalo · wzr-s900dhp firmware27 Mar 2026
- CVE-2026-3266934İzleyin
Code injection vulnerability exists in BUFFALO Wi-Fi router products.
YüksekCVSS 8,7İstismar yokEPSS %0buffalo · wcr-1166dhpl firmware27 Mar 2026
- CVE-2026-4577834İzleyin
Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Reset
YüksekCVSS 8,6İstismar yokEPSS %0buffalo · open xdmod5 Haz 2026
- CVE-2021-2009232İzleyin
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict acce
YüksekCVSS 7,5Kavram kanıtıEPSS %8buffalo · wsr-2533dhpl2-bk firmware29 Nis 2021