Vulnerabilities > Buffalo > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-09 CVE-2018-0523 OS Command Injection vulnerability in Buffalo Wxr-1900Dhp2 Firmware 2.48
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
low complexity
buffalo CWE-78
8.8
2018-03-09 CVE-2018-0522 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Buffalo Wxr-1900Dhp2 Firmware 2.48
Buffer overflow in Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary code via a specially crafted file.
local
low complexity
buffalo CWE-119
7.8
2018-03-09 CVE-2018-0521 Missing Authentication for Critical Function vulnerability in Buffalo Wxr-1900Dhp2 Firmware 2.48
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors.
low complexity
buffalo CWE-306
8.8
2017-07-22 CVE-2017-2273 Cross-Site Request Forgery (CSRF) vulnerability in Buffalo Wmr-433 Firmware and Wmr-433W Firmware
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
low complexity
buffalo CWE-352
8.8
2016-06-19 CVE-2016-4815 Path Traversal vulnerability in Buffalo products
Directory traversal vulnerability on BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices with firmware 2.16 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
network
low complexity
buffalo CWE-22
7.5