8.8

CVE-2022-40966

Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the device. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and earlier, WHR-HP-GN firmware Ver. 1.87 and earlier, WPL-05G300 firmware Ver. 1.88 and earlier, WRM-D2133HP firmware Ver. 2.85 and earlier, WRM-D2133HS firmware Ver. 2.96 and earlier, WTR-M2133HP firmware Ver. 2.85 and earlier, WTR-M2133HS firmware Ver. 2.96 and earlier, WXR-1900DHP firmware Ver. 2.50 and earlier, WXR-1900DHP2 firmware Ver. 2.59 and earlier, WXR-1900DHP3 firmware Ver. 2.63 and earlier, WXR-5950AX12 firmware Ver. 3.40 and earlier, WXR-6000AX12B firmware Ver. 3.40 and earlier, WXR-6000AX12S firmware Ver. 3.40 and earlier, WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, WZR-1750DHP2 firmware Ver. 2.31 and earlier, WZR-HP-AG300H firmware Ver. 1.76 and earlier, WZR-HP-G302H firmware Ver. 1.86 and earlier, WEM-1266 firmware Ver. 2.85 and earlier, WEM-1266WP firmware Ver. 2.85 and earlier, WLAE-AG300N firmware Ver. 1.86 and earlier, FS-600DHP firmware Ver. 3.40 and earlier, FS-G300N firmware Ver. 3.14 and earlier, FS-HP-G300N firmware Ver. 3.33 and earlier, FS-R600DHP firmware Ver. 3.40 and earlier, BHR-4GRV firmware Ver. 2.00 and earlier, DWR-HP-G300NH firmware Ver. 1.84 and earlier, DWR-PG firmware Ver. 1.83 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WER-A54G54 firmware Ver. 1.43 and earlier, WER-AG54 firmware Ver. 1.43 and earlier, WER-AM54G54 firmware Ver. 1.43 and earlier, WER-AMG54 firmware Ver. 1.43 and earlier, WHR-300 firmware Ver. 2.00 and earlier, WHR-300HP firmware Ver. 2.00 and earlier, WHR-AM54G54 firmware Ver. 1.43 and earlier, WHR-AMG54 firmware Ver. 1.43 and earlier, WHR-AMPG firmware Ver. 1.52 and earlier, WHR-G firmware Ver. 1.49 and earlier, WHR-G300N firmware Ver. 1.65 and earlier, WHR-G301N firmware Ver. 1.87 and earlier, WHR-G54S firmware Ver. 1.43 and earlier, WHR-G54S-NI firmware Ver. 1.24 and earlier, WHR-HP-AMPG firmware Ver. 1.43 and earlier, WHR-HP-G firmware Ver. 1.49 and earlier, WHR-HP-G54 firmware Ver. 1.43 and earlier, WLI-H4-D600 firmware Ver. 1.88 and earlier, WS024BF firmware Ver. 1.60 and earlier, WS024BF-NW firmware Ver. 1.60 and earlier, WXR-1750DHP firmware Ver. 2.60 and earlier, WXR-1750DHP2 firmware Ver. 2.60 and earlier, WZR-1166DHP firmware Ver. 2.18 and earlier, WZR-1166DHP2 firmware Ver. 2.18 and earlier, WZR-1750DHP firmware Ver. 2.30 and earlier, WZR2-G300N firmware Ver. 1.55 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, WZR-600DHP3 firmware Ver. 2.19 and earlier, WZR-900DHP2 firmware Ver. 2.19 and earlier, WZR-AGL300NH firmware Ver. 1.55 and earlier, WZR-AMPG144NH firmware Ver. 1.49 and earlier, WZR-AMPG300NH firmware Ver. 1.51 and earlier, WZR-D1100H firmware Ver. 2.00 and earlier, WZR-G144N firmware Ver. 1.48 and earlier, WZR-G144NH firmware Ver. 1.48 and earlier, WZR-HP-G300NH firmware Ver. 1.84 and earlier, WZR-HP-G301NH firmware Ver. 1.84 and earlier, WZR-HP-G450H firmware Ver. 1.90 and earlier, WZR-S1750DHP firmware Ver. 2.32 and earlier, WZR-S600DHP firmware Ver. 2.19 and earlier, and WZR-S900DHP firmware Ver. 2.19 and earlier.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BuffaloWcr-300 Firmware Version <= 1.87
   BuffaloWcr-300 Version-
BuffaloWhr-hp-g300n Firmware Version <= 2.00
   BuffaloWhr-hp-g300n Version-
BuffaloWhr-hp-gn Firmware Version <= 1.87
   BuffaloWhr-hp-gn Version-
BuffaloWpl-05g300 Firmware Version <= 1.88
   BuffaloWpl-05g300 Version-
BuffaloWrm-d2133hp Firmware Version <= 2.85
   BuffaloWrm-d2133hp Version-
BuffaloWrm-d2133hs Firmware Version <= 2.96
   BuffaloWrm-d2133hs Version-
BuffaloWtr-m2133hp Firmware Version <= 2.85
   BuffaloWtr-m2133hp Version-
BuffaloWtr-m2133hs Firmware Version <= 2.96
   BuffaloWtr-m2133hs Version-
BuffaloWxr-1900dhp Firmware Version <= 2.50
   BuffaloWxr-1900dhp Version-
BuffaloWxr-1900dhp2 Firmware Version <= 2.59
   BuffaloWxr-1900dhp2 Version-
BuffaloWxr-1900dhp3 Firmware Version <= 2.63
   BuffaloWxr-1900dhp3 Version-
BuffaloWxr-5950ax12 Firmware Version <= 3.40
   BuffaloWxr-5950ax12 Version-
BuffaloWxr-6000ax12b Firmware Version <= 3.40
   BuffaloWxr-6000ax12b Version-
BuffaloWxr-6000ax12s Firmware Version <= 3.40
   BuffaloWxr-6000ax12s Version-
BuffaloWzr-300hp Firmware Version <= 2.00
   BuffaloWzr-300hp Version-
BuffaloWzr-450hp Firmware Version <= 2.00
   BuffaloWzr-450hp Version-
BuffaloWzr-600dhp Firmware Version <= 2.00
   BuffaloWzr-600dhp Version-
BuffaloWzr-900dhp Firmware Version <= 1.15
   BuffaloWzr-900dhp Version-
BuffaloWzr-1750dhp2 Firmware Version <= 2.31
   BuffaloWzr-1750dhp2 Version-
BuffaloWzr-hp-ag300h Firmware Version <= 1.76
   BuffaloWzr-hp-ag300h Version-
BuffaloWzr-hp-g302h Firmware Version <= 1.86
   BuffaloWzr-hp-g302h Version-
BuffaloWem-1266 Firmware Version <= 2.85
   BuffaloWem-1266 Version-
BuffaloWem-1266wp Firmware Version <= 2.85
   BuffaloWem-1266wp Version-
BuffaloWlae-ag300n Firmware Version <= 1.86
   BuffaloWlae-ag300n Version-
BuffaloFs-600dhp Firmware Version <= 3.40
   BuffaloFs-600dhp Version-
BuffaloFs-g300n Firmware Version <= 3.14
   BuffaloFs-g300n Version-
BuffaloFs-hp-g300n Firmware Version <= 3.33
   BuffaloFs-hp-g300n Version-
BuffaloFs-r600dhp Firmware Version <= 3.40
   BuffaloFs-r600dhp Version-
BuffaloBhr-4grv Firmware Version <= 2.00
   BuffaloBhr-4grv Version-
BuffaloDwr-hp-g300nh Firmware Version <= 1.84
   BuffaloDwr-hp-g300nh Version-
BuffaloDwr-pg Firmware Version <= 1.83
   BuffaloDwr-pg Version-
BuffaloHw-450hp-zwe Firmware Version <= 2.00
   BuffaloHw-450hp-zwe Version-
BuffaloWer-a54g54 Firmware Version <= 1.43
   BuffaloWer-a54g54 Version-
BuffaloWer-ag54 Firmware Version <= 1.43
   BuffaloWer-ag54 Version-
BuffaloWer-am54g54 Firmware Version <= 1.43
   BuffaloWer-am54g54 Version-
BuffaloWer-amg54 Firmware Version <= 1.43
   BuffaloWer-amg54 Version-
BuffaloWhr-300 Firmware Version <= 2.00
   BuffaloWhr-300 Version-
BuffaloWhr-300hp Firmware Version <= 2.00
   BuffaloWhr-300hp Version-
BuffaloWhr-am54g54 Firmware Version <= 1.43
   BuffaloWhr-am54g54 Version-
BuffaloWhr-amg54 Firmware Version <= 1.43
   BuffaloWhr-amg54 Version-
BuffaloWhr-ampg Firmware Version <= 1.52
   BuffaloWhr-ampg Version-
BuffaloWhr-g Firmware Version <= 1.49
   BuffaloWhr-g Version-
BuffaloWhr-g300n Firmware Version <= 1.65
   BuffaloWhr-g300n Version-
BuffaloWhr-g301n Firmware Version <= 1.87
   BuffaloWhr-g301n Version-
BuffaloWhr-g54s Firmware Version <= 1.43
   BuffaloWhr-g54s Version-
BuffaloWhr-g54s-ni Firmware Version <= 1.24
   BuffaloWhr-g54s-ni Version-
BuffaloWhr-hp-ampg Firmware Version <= 1.43
   BuffaloWhr-hp-ampg Version-
BuffaloWhr-hp-g Firmware Version <= 1.49
   BuffaloWhr-hp-g Version-
BuffaloWhr-hp-g54 Firmware Version <= 1.43
   BuffaloWhr-hp-g54 Version-
BuffaloWli-h4-d600 Firmware Version <= 1.88
   BuffaloWli-h4-d600 Version-
BuffaloWs024bf Firmware Version <= 1.60
   BuffaloWs024bf Version-
BuffaloWs024bf-nw Firmware Version <= 1.60
   BuffaloWs024bf-nw Version-
BuffaloWxr-1750dhp Firmware Version <= 2.60
   BuffaloWxr-1750dhp Version-
BuffaloWxr-1750dhp2 Firmware Version <= 2.60
   BuffaloWxr-1750dhp2 Version-
BuffaloWzr-1166dhp Firmware Version <= 2.18
   BuffaloWzr-1166dhp Version-
BuffaloWzr-1166dhp2 Firmware Version <= 2.18
   BuffaloWzr-1166dhp2 Version-
BuffaloWzr-1750dhp Firmware Version <= 2.30
   BuffaloWzr-1750dhp Version-
BuffaloWzr2-g300n Firmware Version <= 1.55
   BuffaloWzr2-g300n Version-
BuffaloWzr-450hp-cwt Firmware Version <= 2.00
   BuffaloWzr-450hp-cwt Version-
BuffaloWzr-450hp-ub Firmware Version <= 2.00
   BuffaloWzr-450hp-ub Version-
BuffaloWzr-600dhp2 Firmware Version <= 1.15
   BuffaloWzr-600dhp2 Version-
BuffaloWzr-600dhp3 Firmware Version <= 2.19
   BuffaloWzr-600dhp3 Version-
BuffaloWzr-900dhp2 Firmware Version <= 2.19
   BuffaloWzr-900dhp2 Version-
BuffaloWzr-agl300nh Firmware Version <= 1.55
   BuffaloWzr-agl300nh Version-
BuffaloWzr-ampg144nh Firmware Version <= 1.49
   BuffaloWzr-ampg144nh Version-
BuffaloWzr-ampg300nh Firmware Version <= 1.51
   BuffaloWzr-ampg300nh Version-
BuffaloWzr-d1100h Firmware Version <= 2.00
   BuffaloWzr-d1100h Version-
BuffaloWzr-g144n Firmware Version <= 1.48
   BuffaloWzr-g144n Version-
BuffaloWzr-g144nh Firmware Version <= 1.48
   BuffaloWzr-g144nh Version-
BuffaloWzr-hp-g300nh Firmware Version <= 1.84
   BuffaloWzr-hp-g300nh Version-
BuffaloWzr-hp-g301nh Firmware Version <= 1.84
   BuffaloWzr-hp-g301nh Version-
BuffaloWzr-hp-g450h Firmware Version <= 1.90
   BuffaloWzr-hp-g450h Version-
BuffaloWzr-s1750dhp Firmware Version <= 2.32
   BuffaloWzr-s1750dhp Version-
BuffaloWzr-s600dhp Firmware Version <= 2.19
   BuffaloWzr-s600dhp Version-
BuffaloWzr-s900dhp Firmware Version <= 2.19
   BuffaloWzr-s900dhp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.17% 0.386
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-287 Improper Authentication

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.