All the vulnerabilites related to BUFFALO INC. - WZR-RS-G54HP firmware
jvndb-2021-001380
Vulnerability from jvndb
Published
2021-04-28 16:15
Modified
2021-05-07 16:16
Severity ?
Summary
Multiple Buffalo network devices contain hidden functionality
Details
Multiple network devices provided by BUFFALO INC. contain hidden functionality (CWE-912) that allows an attacker to enable the debug option. Chuya Hayakawa of 00One, Inc. reported this vulnerability to JPCERT/CC. JPCERT/CC coordinated with the developer.
Show details on JVN DB website


{
  "@rdf:about": "https://jvndb.jvn.jp/en/contents/2021/JVNDB-2021-001380.html",
  "dc:date": "2021-05-07T16:16+09:00",
  "dcterms:issued": "2021-04-28T16:15+09:00",
  "dcterms:modified": "2021-05-07T16:16+09:00",
  "description": "Multiple network devices provided by BUFFALO INC. contain hidden functionality (CWE-912) that allows an attacker to enable the debug option.\r\n\r\nChuya Hayakawa of 00One, Inc. reported this vulnerability to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.",
  "link": "https://jvndb.jvn.jp/en/contents/2021/JVNDB-2021-001380.html",
  "sec:cpe": [
    {
      "#text": "cpe:/o:buffalo_inc:bhr-4rv_firmware",
      "@product": "BHR-4RV firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:fs-g54_firmware",
      "@product": "FS-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wbr-b11_firmware",
      "@product": "WBR-B11 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wbr-g54l_firmware",
      "@product": "WBR-G54L firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wbr-g54_firmware",
      "@product": "WBR-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wbr2-b11_firmware",
      "@product": "WBR2-B11 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wbr2-g54-kd_firmware",
      "@product": "WBR2-G54-KD firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wbr2-g54_firmware",
      "@product": "WBR2-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:whr-g54-nf_firmware",
      "@product": "WHR-G54-NF firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:whr-g54_firmware",
      "@product": "WHR-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:whr2-a54g54_firmware",
      "@product": "WHR2-A54G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:whr2-g54v_firmware",
      "@product": "WHR2-G54V firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:whr2-g54_firmware",
      "@product": "WHR2-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:whr3-ag54_firmware",
      "@product": "WHR3-AG54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wla-b11_firmware",
      "@product": "WLA-B11 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wla-g54c_firmware",
      "@product": "WLA-G54C firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wla-g54_firmware",
      "@product": "WLA-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wla2-g54c_firmware",
      "@product": "WLA2-G54C firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wla2-g54_firmware",
      "@product": "WLA2-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wlah-a54g54_firmware",
      "@product": "WLAH-A54G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wlah-am54g54_firmware",
      "@product": "WLAH-AM54G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wlah-g54_firmware",
      "@product": "WLAH-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wli-t1-b11_firmware",
      "@product": "WLI-T1-B11 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wli-tx1-g54_firmware",
      "@product": "WLI-TX1-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wli2-tx1-ag54_firmware",
      "@product": "WLI2-TX1-AG54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wli2-tx1-amg54_firmware",
      "@product": "WLI2-TX1-AMG54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wli2-tx1-g54_firmware",
      "@product": "WLI2-TX1-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wli3-tx1-amg54_firmware",
      "@product": "WLI3-TX1-AMG54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wli3-tx1-g54_firmware",
      "@product": "WLI3-TX1-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wvr-g54-nf_firmware",
      "@product": "WVR-G54-NF firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wzr-g108_firmware",
      "@product": "WZR-G108 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wzr-g54_firmware",
      "@product": "WZR-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wzr-hp-g54_firmware",
      "@product": "WZR-HP-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wzr-rs-g54hp_firmware",
      "@product": "WZR-RS-G54HP firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wzr-rs-g54_firmware",
      "@product": "WZR-RS-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    }
  ],
  "sec:cvss": [
    {
      "@score": "10.0",
      "@severity": "High",
      "@type": "Base",
      "@vector": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
      "@version": "2.0"
    },
    {
      "@score": "8.8",
      "@severity": "High",
      "@type": "Base",
      "@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
      "@version": "3.0"
    }
  ],
  "sec:identifier": "JVNDB-2021-001380",
  "sec:references": [
    {
      "#text": "https://jvn.jp/en/vu/JVNVU90274525/index.html",
      "@id": "JVNVU#90274525",
      "@source": "JVN"
    },
    {
      "#text": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20716",
      "@id": "CVE-2021-20716",
      "@source": "CVE"
    },
    {
      "#text": "https://nvd.nist.gov/vuln/detail/CVE-2021-20716",
      "@id": "CVE-2021-20716",
      "@source": "NVD"
    },
    {
      "#text": "https://cwe.mitre.org/data/definitions/912.html",
      "@id": "CWE-912",
      "@title": "Hidden Functionality(CWE-912)"
    }
  ],
  "title": "Multiple Buffalo network devices contain hidden functionality"
}

jvndb-2007-000875
Vulnerability from jvndb
Published
2008-05-21 00:00
Modified
2008-05-21 00:00
Severity ?
() - -
Summary
AirStation series and BroadStation series vulnerable to cross-site request forgery
Details
Buffalo's AirStation Series and BroadStation Series routers are vulnerable to cross-site request forgery. Buffalo's AirStation series and BroadStation series routers have a web administration interface that can be accessed from a web browser to configure their functional settings. The web administration interface is vulnerable to cross-site request forgery.
References
Show details on JVN DB website


{
  "@rdf:about": "https://jvndb.jvn.jp/en/contents/2007/JVNDB-2007-000875.html",
  "dc:date": "2008-05-21T00:00+09:00",
  "dcterms:issued": "2008-05-21T00:00+09:00",
  "dcterms:modified": "2008-05-21T00:00+09:00",
  "description": "Buffalo\u0027s AirStation Series and BroadStation Series routers are vulnerable to cross-site request forgery.\r\n\r\nBuffalo\u0027s AirStation series and BroadStation series routers have a web administration interface that can be accessed from a web browser to configure their functional settings. The web administration interface is vulnerable to cross-site request forgery.",
  "link": "https://jvndb.jvn.jp/en/contents/2007/JVNDB-2007-000875.html",
  "sec:cpe": [
    {
      "#text": "cpe:/o:buffalo_inc:bhr-4rv_firmware",
      "@product": "BHR-4RV firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:whr2-g54v_firmware",
      "@product": "WHR2-G54V firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wzr-rs-g54hp_firmware",
      "@product": "WZR-RS-G54HP firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    },
    {
      "#text": "cpe:/o:buffalo_inc:wzr-rs-g54_firmware",
      "@product": "WZR-RS-G54 firmware",
      "@vendor": "BUFFALO INC.",
      "@version": "2.2"
    }
  ],
  "sec:cvss": {
    "@score": "4.0",
    "@severity": "Medium",
    "@type": "Base",
    "@vector": "AV:N/AC:H/Au:N/C:N/I:P/A:P",
    "@version": "2.0"
  },
  "sec:identifier": "JVNDB-2007-000875",
  "sec:references": {
    "#text": "http://jvn.jp/en/jp/JVN71872818/index.html",
    "@id": "JVN#71872818",
    "@source": "JVN"
  },
  "title": "AirStation series and BroadStation series vulnerable to cross-site request forgery"
}