5.8
CVE-2011-1324
- EPSS 0.12%
- Veröffentlicht 09.05.2011 19:55:03
- Zuletzt bearbeitet 11.04.2025 00:51:21
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify settings, as demonstrated by changing the login password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Buffalotech ≫ Bbr-4hg Firmware Version1.02
Buffalotech ≫ Bbr-4hg Firmware Version1.04
Buffalotech ≫ Bbr-4hg Firmware Version1.04 Updatebeta
Buffalotech ≫ Bbr-4hg Firmware Version1.10
Buffalotech ≫ Bbr-4hg Firmware Version1.10 Updatebeta
Buffalotech ≫ Bbr-4hg Firmware Version1.11 Updatebeta
Buffalotech ≫ Bbr-4hg Firmware Version1.12
Buffalotech ≫ Bbr-4hg Firmware Version1.20
Buffalotech ≫ Bbr-4hg Firmware Version1.20 Updatebeta
Buffalotech ≫ Bbr-4hg Firmware Version1.30
Buffalotech ≫ Bbr-4hg Firmware Version1.30 Updatebeta
Buffalotech ≫ Bbr-4hg Firmware Version1.31
Buffalotech ≫ Bbr-4hg Firmware Version1.32
Buffalotech ≫ Bbr-4hg Firmware Version1.32 Updatebeta
Buffalotech ≫ Bbr-4hg Firmware Version1.33 Updatebeta
Buffalotech ≫ Bbr-4mg Firmware Version1.00
Buffalotech ≫ Bbr-4mg Firmware Version1.01 Updatebeta
Buffalotech ≫ Bbr-4mg Firmware Version1.03
Buffalotech ≫ Bbr-4mg Firmware Version1.04
Buffalotech ≫ Bbr-4mg Firmware Version1.04 Updatebeta
Buffalotech ≫ Bbr-4mg Firmware Version1.10
Buffalotech ≫ Bbr-4mg Firmware Version1.10 Updatebeta
Buffalotech ≫ Bbr-4mg Firmware Version1.11 Updatebeta
Buffalotech ≫ Bbr-4mg Firmware Version1.12
Buffalotech ≫ Bbr-4mg Firmware Version1.20
Buffalotech ≫ Bbr-4mg Firmware Version1.20 Updatebeta
Buffalotech ≫ Bbr-4mg Firmware Version1.30
Buffalotech ≫ Bbr-4mg Firmware Version1.30 Updatebeta
Buffalotech ≫ Bbr-4mg Firmware Version1.31
Buffalotech ≫ Bbr-4mg Firmware Version1.32
Buffalotech ≫ Bbr-4mg Firmware Version1.32 Updatebeta
Buffalotech ≫ Bbr-4mg Firmware Version1.33
Buffalotech ≫ Bbr-4mg Firmware Version1.33 Updatebeta
Buffalotech ≫ Bhr-4rv Firmware Version2.31
Buffalotech ≫ Bhr-4rv Firmware Version2.32 Updateprebeta
Buffalotech ≫ Bhr-4rv Firmware Version2.33 Updateprebeta
Buffalotech ≫ Bhr-4rv Firmware Version2.42
Buffalotech ≫ Bhr-4rv Firmware Version2.46
Buffalotech ≫ Bhr-4rv Firmware Version2.48
Buffalotech ≫ Fs-g54 Firmware Version2.07
Buffalotech ≫ Wer-a54g54 Firmware Version1.00
Buffalotech ≫ Wer-a54g54 Firmware Version1.01 Updatebeta
Buffalotech ≫ Wer-a54g54 Firmware Version1.02
Buffalotech ≫ Wer-a54g54 Firmware Version1.03
Buffalotech ≫ Wer-a54g54 Firmware Version1.10
Buffalotech ≫ Wer-a54g54 Firmware Version1.12
Buffalotech ≫ Wer-a54g54 Firmware Version1.12 Updatebeta
Buffalotech ≫ Wer-a54g54 Firmware Version1.13
Buffalotech ≫ Wer-ag54 Firmware Version1.04
Buffalotech ≫ Wer-ag54 Firmware Version1.12
Buffalotech ≫ Wer-ag54 Firmware Version1.12 Updatebeta
Buffalotech ≫ Wer-am54g54 Firmware Version1.11
Buffalotech ≫ Wer-am54g54 Firmware Version1.12
Buffalotech ≫ Wer-am54g54 Firmware Version1.12 Updatebeta
Buffalotech ≫ Wer-am54g54 Firmware Version1.13
Buffalotech ≫ Wer-am54g54 Firmware Version1.14
Buffalotech ≫ Wer-amg54 Firmware Version1.11
Buffalotech ≫ Wer-amg54 Firmware Version1.12
Buffalotech ≫ Wer-amg54 Firmware Version1.14
Buffalotech ≫ Whr-am54g54 Firmware Version1.30
Buffalotech ≫ Whr-am54g54 Firmware Version1.38
Buffalotech ≫ Whr-am54g54 Firmware Version1.40
Buffalotech ≫ Whr-am54g54 Firmware Version1.42
Buffalotech ≫ Whr-amg54 Firmware Version1.31
Buffalotech ≫ Whr-amg54 Firmware Version1.38
Buffalotech ≫ Whr-amg54 Firmware Version1.40
Buffalotech ≫ Whr-amg54 Firmware Version1.42
Buffalotech ≫ Whr-ampg Firmware Version1.46
Buffalotech ≫ Whr-g Firmware Version1.46
Buffalotech ≫ Whr-g54s Firmware Version1.20
Buffalotech ≫ Whr-g54s Firmware Version1.21
Buffalotech ≫ Whr-g54s Firmware Version1.23
Buffalotech ≫ Whr-g54s Firmware Version1.38
Buffalotech ≫ Whr-g54s Firmware Version1.40
Buffalotech ≫ Whr-g54s Firmware Version1.42
Buffalotech ≫ Whr-hp-ampg Firmware Version1.32
Buffalotech ≫ Whr-hp-g Firmware Version1.46
Buffalotech ≫ Whr-hp-g54 Firmware Version1.20
Buffalotech ≫ Whr-hp-g54 Firmware Version1.21
Buffalotech ≫ Whr-hp-g54 Firmware Version1.23
Buffalotech ≫ Whr-hp-g54 Firmware Version1.38
Buffalotech ≫ Whr-hp-g54 Firmware Version1.40
Buffalotech ≫ Whr-hp-g54 Firmware Version1.42
Buffalotech ≫ Wzr-ampg144nh Firmware Version1.47
Buffalotech ≫ Wzr-ampg144nh Firmware Version1.48 Updatebeta
Buffalotech ≫ Wzr-ampg300nh Firmware Version1.48
Buffalotech ≫ Wzr-g144n Firmware Version1.45
Buffalotech ≫ Wzr-g144n Firmware Version1.46 Updatebeta
Buffalotech ≫ Wzr-g144n Firmware Version1.47
Buffalotech ≫ Wzr-g144n Firmware Version1.47 Updatebeta
Buffalotech ≫ Wzr-g144nh Firmware Version1.45
Buffalotech ≫ Wzr-g144nh Firmware Version1.47
Buffalotech ≫ Wzr-g144nh Firmware Version1.47 Updatebeta
Buffalotech ≫ Wzr-g144nh Firmware Version1.48
Buffalotech ≫ Wzr2-g300n Firmware Version1.48
Buffalotech ≫ Wzr2-g300n Firmware Version1.50 Updatebeta
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.271 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:P
|
CWE-352 Cross-Site Request Forgery (CSRF)
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.