5.8

CVE-2011-1324

Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify settings, as demonstrated by changing the login password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BuffalotechBbr-4hg Firmware Version1.02
BuffalotechBbr-4hg Firmware Version1.04
BuffalotechBbr-4hg Firmware Version1.04 Updatebeta
BuffalotechBbr-4hg Firmware Version1.10
BuffalotechBbr-4hg Firmware Version1.10 Updatebeta
BuffalotechBbr-4hg Firmware Version1.11 Updatebeta
BuffalotechBbr-4hg Firmware Version1.12
BuffalotechBbr-4hg Firmware Version1.20
BuffalotechBbr-4hg Firmware Version1.20 Updatebeta
BuffalotechBbr-4hg Firmware Version1.30
BuffalotechBbr-4hg Firmware Version1.30 Updatebeta
BuffalotechBbr-4hg Firmware Version1.31
BuffalotechBbr-4hg Firmware Version1.32
BuffalotechBbr-4hg Firmware Version1.32 Updatebeta
BuffalotechBbr-4hg Firmware Version1.33 Updatebeta
BuffalotechBbr-4mg Firmware Version1.00
BuffalotechBbr-4mg Firmware Version1.01 Updatebeta
BuffalotechBbr-4mg Firmware Version1.03
BuffalotechBbr-4mg Firmware Version1.04
BuffalotechBbr-4mg Firmware Version1.04 Updatebeta
BuffalotechBbr-4mg Firmware Version1.10
BuffalotechBbr-4mg Firmware Version1.10 Updatebeta
BuffalotechBbr-4mg Firmware Version1.11 Updatebeta
BuffalotechBbr-4mg Firmware Version1.12
BuffalotechBbr-4mg Firmware Version1.20
BuffalotechBbr-4mg Firmware Version1.20 Updatebeta
BuffalotechBbr-4mg Firmware Version1.30
BuffalotechBbr-4mg Firmware Version1.30 Updatebeta
BuffalotechBbr-4mg Firmware Version1.31
BuffalotechBbr-4mg Firmware Version1.32
BuffalotechBbr-4mg Firmware Version1.32 Updatebeta
BuffalotechBbr-4mg Firmware Version1.33
BuffalotechBbr-4mg Firmware Version1.33 Updatebeta
BuffalotechBhr-4rv Firmware Version2.31
BuffalotechBhr-4rv Firmware Version2.32 Updateprebeta
BuffalotechBhr-4rv Firmware Version2.33 Updateprebeta
BuffalotechBhr-4rv Firmware Version2.42
BuffalotechBhr-4rv Firmware Version2.46
BuffalotechBhr-4rv Firmware Version2.48
BuffalotechFs-g54 Firmware Version2.07
BuffalotechWer-a54g54 Firmware Version1.01 Updatebeta
BuffalotechWer-a54g54 Firmware Version1.12 Updatebeta
BuffalotechWer-ag54 Firmware Version1.04
BuffalotechWer-ag54 Firmware Version1.12
BuffalotechWer-ag54 Firmware Version1.12 Updatebeta
BuffalotechWer-am54g54 Firmware Version1.12 Updatebeta
BuffalotechWhr-ampg Firmware Version1.46
BuffalotechWhr-g Firmware Version1.46
BuffalotechWhr-g54s Firmware Version1.20
BuffalotechWhr-g54s Firmware Version1.21
BuffalotechWhr-g54s Firmware Version1.23
BuffalotechWhr-g54s Firmware Version1.38
BuffalotechWhr-g54s Firmware Version1.40
BuffalotechWhr-g54s Firmware Version1.42
BuffalotechWhr-hp-g Firmware Version1.46
BuffalotechWzr-ampg144nh Firmware Version1.48 Updatebeta
BuffalotechWzr-g144n Firmware Version1.46 Updatebeta
BuffalotechWzr-g144n Firmware Version1.47 Updatebeta
BuffalotechWzr-g144nh Firmware Version1.47 Updatebeta
BuffalotechWzr2-g300n Firmware Version1.50 Updatebeta
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.271
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:N/I:P/A:P
CWE-352 Cross-Site Request Forgery (CSRF)

The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.