Skip to content
Noroxi

Buffalo records

61 published records for vendor buffalo.

All records

61 records
  • A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <=

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    buffalo · wsr-2533dhpl2-bk firmwareApr 29, 2021

  • Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified

    CriticalCVSS 9.8No exploitEPSS 23%

    buffalo · ts5600d1206 firmwareNov 26, 2018

  • WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and

    CriticalCVSS 9.8No exploitEPSS 4%

    buffalo · wapm-1166d firmwareJul 21, 2017

  • Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11

    CriticalCVSS 9.8No exploitEPSS 3%

    buffalo · bhr-4rv firmwareApr 27, 2021

  • An issue was discovered in Open XDMoD through 7.5.0.

    CriticalCVSS 9.8No exploitEPSS 2%

    buffalo · open xdmodMay 2, 2019

  • Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wi

    CriticalCVSS 9.8No exploitEPSS 1%

    buffalo · wsr-2533dhp firmwareApr 15, 2024

  • The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user

    HighCVSS 8.8Proof of conceptEPSS 9%

    buffalo · wsr-2533dhpl2-bk firmwareApr 29, 2021

  • Open XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Database Compromise

    CriticalCVSS 9.3No exploitEPSS 1%

    buffalo · open xdmodJun 5, 2026

  • Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command Injection

    CriticalCVSS 9.3No exploitEPSS 1%

    buffalo · open xdmodJun 5, 2026

  • Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal functions via the "m

    HighCVSS 8.8No exploitEPSS 1%

    buffalo · ts5600d1206 firmwareNov 26, 2018

  • CVE-2021-3512
    35Monitor

    Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 an

    HighCVSS 8.8No exploitEPSS 1%

    buffalo · bhr-4grv firmwareApr 27, 2021

  • CVE-2018-0554
    35Monitor

    Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspe

    HighCVSS 8.8No exploitEPSS 1%

    buffalo · wzr-1750dhp2 firmwareApr 9, 2018

  • CVE-2018-0521
    35Monitor

    Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device

    HighCVSS 8.8No exploitEPSS 1%

    buffalo · wxr-1900dhp2 firmwareMar 9, 2018

  • OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a sp

    HighCVSS 8.8No exploitEPSS 1%

    buffalo · wsr-3200ax4s firmwareDec 18, 2022

  • CVE-2017-2273
    35Monitor

    Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remo

    HighCVSS 8.8No exploitEPSS 1%

    buffalo · wmr-433 firmwareJul 21, 2017

  • CVE-2018-0556
    35Monitor

    Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

    HighCVSS 8.8No exploitEPSS 1%

    buffalo · wzr-1750dhp2 firmwareApr 9, 2018

  • CVE-2018-0523
    35Monitor

    Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

    HighCVSS 8.8No exploitEPSS 1%

    buffalo · wxr-1900dhp2 firmwareMar 9, 2018

  • WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands wit

    HighCVSS 8.8No exploitEPSS 1%

    buffalo · wsr-1166dhp4 firmwareJun 8, 2021

  • Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and acce

    HighCVSS 8.8No exploitEPSS 0%

    buffalo · wcr-300 firmwareDec 7, 2022

  • OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products.

    HighCVSS 8.6No exploitEPSS 1%

    buffalo · wcr-1166dhpl firmwareMar 27, 2026

  • Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging fu

    HighCVSS 8.6No exploitEPSS 1%

    buffalo · wcr-1166dhpl firmwareMar 27, 2026

  • Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings wi

    HighCVSS 8.7No exploitEPSS 1%

    buffalo · wzr-s900dhp firmwareMar 27, 2026

  • Code injection vulnerability exists in BUFFALO Wi-Fi router products.

    HighCVSS 8.7No exploitEPSS 0%

    buffalo · wcr-1166dhpl firmwareMar 27, 2026

  • Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Reset

    HighCVSS 8.6No exploitEPSS 0%

    buffalo · open xdmodJun 5, 2026

  • The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict acce

    HighCVSS 7.5Proof of conceptEPSS 8%

    buffalo · wsr-2533dhpl2-bk firmwareApr 29, 2021