Записи Buffalo
61 опубликованных записей вендора buffalo.
Профиль для исследователя
- Попали в KEV
- 1 · 1,6 %
- С эксплойтом
- 1 · 1,6 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 188 дн.
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-306 Missing Authentication for Critical Function3
- CWE-287 Improper Authentication3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
61 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2021-20090Готовый эксплойт | A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= buffalo · wsr-2533dhpl2-bk firmware · CWE-22 | Критическая9,8 | KEV | 100,0 % | 29 апр. 2021 г. |
46В плане | CVE-2018-13324Эксплойта нет | Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified buffalo · ts5600d1206 firmware · CWE-863 | Критическая9,8 | — | 23,2 % | 26 нояб. 2018 г. |
40В плане | CVE-2017-2126Эксплойта нет | WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication andbuffalo · wapm-1166d firmware · CWE-287 | Критическая9,8 | — | 4,0 % | 21 июл. 2017 г. |
40В плане | CVE-2021-20716Эксплойта нет | Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 buffalo · bhr-4rv firmware | Критическая9,8 | — | 3,2 % | 27 апр. 2021 г. |
39Наблюдать | CVE-2018-16988Эксплойта нет | An issue was discovered in Open XDMoD through 7.5.0.buffalo · open xdmod · CWE-640 | Критическая9,8 | — | 1,6 % | 2 мая 2019 г. |
39Наблюдать | CVE-2024-23486Эксплойта нет | Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wibuffalo · wsr-2533dhp firmware · CWE-256 | Критическая9,8 | — | 0,6 % | 15 апр. 2024 г. |
38Наблюдать | CVE-2021-20091Proof of concept | The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize userbuffalo · wsr-2533dhpl2-bk firmware | Высокая8,8 | — | 8,8 % | 29 апр. 2021 г. |
37Наблюдать | CVE-2026-45779Эксплойта нет | Open XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Database Compromisebuffalo · open xdmod · CWE-89 | Критическая9,3 | — | 0,9 % | 5 июн. 2026 г. |
37Наблюдать | CVE-2026-45777Эксплойта нет | Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command Injectionbuffalo · open xdmod · CWE-78 | Критическая9,3 | — | 0,7 % | 5 июн. 2026 г. |
35Наблюдать | CVE-2018-13321Эксплойта нет | Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal functions via the "mbuffalo · ts5600d1206 firmware · CWE-732 | Высокая8,8 | — | 1,0 % | 26 нояб. 2018 г. |
35Наблюдать | CVE-2021-3512Эксплойта нет | Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 anbuffalo · bhr-4grv firmware | Высокая8,8 | — | 0,9 % | 27 апр. 2021 г. |
35Наблюдать | CVE-2018-0554Эксплойта нет | Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspebuffalo · wzr-1750dhp2 firmware · CWE-306 | Высокая8,8 | — | 0,8 % | 9 апр. 2018 г. |
35Наблюдать | CVE-2018-0521Эксплойта нет | Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device buffalo · wxr-1900dhp2 firmware · CWE-306 | Высокая8,8 | — | 0,8 % | 9 мар. 2018 г. |
35Наблюдать | CVE-2022-43443Эксплойта нет | OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a spbuffalo · wsr-3200ax4s firmware · CWE-78 | Высокая8,8 | — | 0,8 % | 18 дек. 2022 г. |
35Наблюдать | CVE-2017-2273Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remobuffalo · wmr-433 firmware · CWE-352 | Высокая8,8 | — | 0,8 % | 21 июл. 2017 г. |
35Наблюдать | CVE-2018-0556Эксплойта нет | Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.buffalo · wzr-1750dhp2 firmware · CWE-78 | Высокая8,8 | — | 0,7 % | 9 апр. 2018 г. |
35Наблюдать | CVE-2018-0523Эксплойта нет | Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.buffalo · wxr-1900dhp2 firmware · CWE-78 | Высокая8,8 | — | 0,7 % | 9 мар. 2018 г. |
35Наблюдать | CVE-2021-20731Эксплойта нет | WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands witbuffalo · wsr-1166dhp4 firmware · CWE-78 | Высокая8,8 | — | 0,6 % | 8 июн. 2021 г. |
35Наблюдать | CVE-2022-40966Эксплойта нет | Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and accebuffalo · wcr-300 firmware · CWE-287 | Высокая8,8 | — | 0,4 % | 7 дек. 2022 г. |
34Наблюдать | CVE-2026-27650Эксплойта нет | OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products.buffalo · wcr-1166dhpl firmware · CWE-78 | Высокая8,6 | — | 1,4 % | 27 мар. 2026 г. |
34Наблюдать | CVE-2026-33280Эксплойта нет | Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging fubuffalo · wcr-1166dhpl firmware · CWE-912 | Высокая8,6 | — | 0,7 % | 27 мар. 2026 г. |
34Наблюдать | CVE-2026-32678Эксплойта нет | Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings wibuffalo · wzr-s900dhp firmware · CWE-288 | Высокая8,7 | — | 0,5 % | 27 мар. 2026 г. |
34Наблюдать | CVE-2026-32669Эксплойта нет | Code injection vulnerability exists in BUFFALO Wi-Fi router products.buffalo · wcr-1166dhpl firmware · CWE-94 | Высокая8,7 | — | 0,5 % | 27 мар. 2026 г. |
34Наблюдать | CVE-2026-45778Эксплойта нет | Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Resetbuffalo · open xdmod · CWE-79 | Высокая8,6 | — | 0,2 % | 5 июн. 2026 г. |
32Наблюдать | CVE-2021-20092Proof of concept | The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict accebuffalo · wsr-2533dhpl2-bk firmware · CWE-287 | Высокая7,5 | — | 8,2 % | 29 апр. 2021 г. |
- CVE-2021-2009099Срочно
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <=
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %buffalo · wsr-2533dhpl2-bk firmware29 апр. 2021 г.
- CVE-2018-1332446В плане
Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified
КритическаяCVSS 9,8Эксплойта нетEPSS 23 %buffalo · ts5600d1206 firmware26 нояб. 2018 г.
- CVE-2017-212640В плане
WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %buffalo · wapm-1166d firmware21 июл. 2017 г.
- CVE-2021-2071640В плане
Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %buffalo · bhr-4rv firmware27 апр. 2021 г.
- CVE-2018-1698839Наблюдать
An issue was discovered in Open XDMoD through 7.5.0.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %buffalo · open xdmod2 мая 2019 г.
- CVE-2024-2348639Наблюдать
Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wi
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %buffalo · wsr-2533dhp firmware15 апр. 2024 г.
- CVE-2021-2009138Наблюдать
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user
ВысокаяCVSS 8,8Proof of conceptEPSS 9 %buffalo · wsr-2533dhpl2-bk firmware29 апр. 2021 г.
- CVE-2026-4577937Наблюдать
Open XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Database Compromise
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %buffalo · open xdmod5 июн. 2026 г.
- CVE-2026-4577737Наблюдать
Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command Injection
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %buffalo · open xdmod5 июн. 2026 г.
- CVE-2018-1332135Наблюдать
Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal functions via the "m
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %buffalo · ts5600d1206 firmware26 нояб. 2018 г.
- CVE-2021-351235Наблюдать
Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 an
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %buffalo · bhr-4grv firmware27 апр. 2021 г.
- CVE-2018-055435Наблюдать
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspe
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %buffalo · wzr-1750dhp2 firmware9 апр. 2018 г.
- CVE-2018-052135Наблюдать
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %buffalo · wxr-1900dhp2 firmware9 мар. 2018 г.
- CVE-2022-4344335Наблюдать
OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a sp
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %buffalo · wsr-3200ax4s firmware18 дек. 2022 г.
- CVE-2017-227335Наблюдать
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remo
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %buffalo · wmr-433 firmware21 июл. 2017 г.
- CVE-2018-055635Наблюдать
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %buffalo · wzr-1750dhp2 firmware9 апр. 2018 г.
- CVE-2018-052335Наблюдать
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %buffalo · wxr-1900dhp2 firmware9 мар. 2018 г.
- CVE-2021-2073135Наблюдать
WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands wit
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %buffalo · wsr-1166dhp4 firmware8 июн. 2021 г.
- CVE-2022-4096635Наблюдать
Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and acce
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %buffalo · wcr-300 firmware7 дек. 2022 г.
- CVE-2026-2765034Наблюдать
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products.
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %buffalo · wcr-1166dhpl firmware27 мар. 2026 г.
- CVE-2026-3328034Наблюдать
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging fu
ВысокаяCVSS 8,6Эксплойта нетEPSS 1 %buffalo · wcr-1166dhpl firmware27 мар. 2026 г.
- CVE-2026-3267834Наблюдать
Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings wi
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %buffalo · wzr-s900dhp firmware27 мар. 2026 г.
- CVE-2026-3266934Наблюдать
Code injection vulnerability exists in BUFFALO Wi-Fi router products.
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %buffalo · wcr-1166dhpl firmware27 мар. 2026 г.
- CVE-2026-4577834Наблюдать
Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Reset
ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %buffalo · open xdmod5 июн. 2026 г.
- CVE-2021-2009232Наблюдать
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict acce
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %buffalo · wsr-2533dhpl2-bk firmware29 апр. 2021 г.