Vulnerabilities > Buffalotech > High

DATE CVE VULNERABILITY TITLE RISK
2015-06-09 CVE-2014-9284 OS Command Injection vulnerability in Buffalotech products
The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 and earlier, WEX-300 1.60 and earlier, and BHR-4GRV2 1.04 and earlier routers allow remote authenticated users to execute arbitrary OS commands via unspecified vectors.
low complexity
buffalotech CWE-78
7.7
2006-10-10 CVE-2006-5175 Cross-Site Request Forgery (CSRF) vulnerability in Buffalotech Terastation Hd-Htgl Firmware 2.05Beta1
Cross-site request forgery (CSRF) vulnerability in the administrative interface for the TeraStation HD-HTGL firmware 2.05 beta 1 and earlier allows remote attackers to modify configurations or delete arbitrary data via unspecified vectors.
network
high complexity
buffalotech CWE-352
7.6