buffalotech records
12 published records for vendor buffalotech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-20 Improper Input Validation1
- CWE-284 Improper Access Control1
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
12 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2016-7824No exploit | Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the dbuffalotech · wnc01wh firmware · CWE-284 | High8.8 | — | 1.6% | Jun 9, 2017 |
35Monitor | CVE-2016-7822No exploit | Cross-site request forgery (CSRF) vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows remote attackersbuffalotech · wnc01wh firmware · CWE-352 | High8.8 | — | 1.0% | Jun 9, 2017 |
35Monitor | CVE-2016-1134No exploit | Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1buffalotech · whr-1166dhp · CWE-352 | High8.8 | — | 0.5% | Jan 22, 2016 |
30Monitor | CVE-2014-9284No exploit | The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 buffalotech · wsr-600dhp firmware · CWE-78 | High7.7 | — | 1.1% | Jun 8, 2015 |
27Monitor | CVE-2016-7826No exploit | Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to reabuffalotech · wnc01wh firmware · CWE-22 | Medium6.5 | — | 2.2% | Jun 9, 2017 |
27Monitor | CVE-2016-7825No exploit | Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to reabuffalotech · wnc01wh firmware · CWE-22 | Medium6.5 | — | 2.2% | Jun 9, 2017 |
27Monitor | CVE-2016-7821No exploit | Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the managementbuffalotech · wnc01wh firmware · CWE-20 | Medium6.5 | — | 1.8% | Jun 9, 2017 |
27Monitor | CVE-2015-8262No exploit | Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in the header of a DNS qbuffalotech · airstation extreme n600 firmware | Medium6.8 | — | 1.1% | Dec 26, 2015 |
24Monitor | CVE-2016-1135No exploit | Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 andbuffalotech · wmr-300 · CWE-79 | Medium6.1 | — | 0.8% | Jan 22, 2016 |
23Monitor | CVE-2011-1324No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers wbuffalotech · bbr-4hg firmware · CWE-352 | Medium5.8 | — | 0.5% | May 9, 2011 |
17Monitor | CVE-2007-4822No exploit | Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attackebuffalotech · airstation whr-g54s · CWE-352 | Medium4.3 | — | 0.7% | Sep 11, 2007 |
17Monitor | CVE-2016-7823No exploit | Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to inbuffalotech · wnc01wh firmware · CWE-79 | Medium4.3 | — | 0.5% | Jun 9, 2017 |
- CVE-2016-782435Monitor
Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the d
HighCVSS 8.8No exploitEPSS 2%buffalotech · wnc01wh firmwareJun 9, 2017
- CVE-2016-782235Monitor
Cross-site request forgery (CSRF) vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows remote attackers
HighCVSS 8.8No exploitEPSS 1%buffalotech · wnc01wh firmwareJun 9, 2017
- CVE-2016-113435Monitor
Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1
HighCVSS 8.8No exploitEPSS 1%buffalotech · whr-1166dhpJan 22, 2016
- CVE-2014-928430Monitor
The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60
HighCVSS 7.7No exploitEPSS 1%buffalotech · wsr-600dhp firmwareJun 8, 2015
- CVE-2016-782627Monitor
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to rea
MediumCVSS 6.5No exploitEPSS 2%buffalotech · wnc01wh firmwareJun 9, 2017
- CVE-2016-782527Monitor
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to rea
MediumCVSS 6.5No exploitEPSS 2%buffalotech · wnc01wh firmwareJun 9, 2017
- CVE-2016-782127Monitor
Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the management
MediumCVSS 6.5No exploitEPSS 2%buffalotech · wnc01wh firmwareJun 9, 2017
- CVE-2015-826227Monitor
Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in the header of a DNS q
MediumCVSS 6.8No exploitEPSS 1%buffalotech · airstation extreme n600 firmwareDec 26, 2015
- CVE-2016-113524Monitor
Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and
MediumCVSS 6.1No exploitEPSS 1%buffalotech · wmr-300Jan 22, 2016
- CVE-2011-132423Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers w
MediumCVSS 5.8No exploitEPSS 0%buffalotech · bbr-4hg firmwareMay 9, 2011
- CVE-2007-482217Monitor
Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attacke
MediumCVSS 4.3No exploitEPSS 1%buffalotech · airstation whr-g54sSep 11, 2007
- CVE-2016-782317Monitor
Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to in
MediumCVSS 4.3No exploitEPSS 0%buffalotech · wnc01wh firmwareJun 9, 2017