CVE-2021-3511
4.3
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD
Description
Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP firmware Ver.1.99 and prior, WHR-300 firmware Ver.1.99 and prior, WHR-G301N firmware Ver.1.86 and prior, WHR-HP-G300N firmware Ver.1.99 and prior, WHR-HP-GN firmware Ver.1.86 and prior, WPL-05G300 firmware Ver.1.87 and prior, WZR-450HP-CWT firmware Ver.1.99 and prior, WZR-450HP-UB firmware Ver.1.99 and prior, WZR-HP-AG300H firmware Ver.1.75 and prior, WZR-HP-G300NH firmware Ver.1.83 and prior, WZR-HP-G301NH firmware Ver.1.83 and prior, WZR-HP-G302H firmware Ver.1.85 and prior, WZR-HP-G450H firmware Ver.1.89 and prior, WZR-300HP firmware Ver.1.99 and prior, WZR-450HP firmware Ver.1.99 and prior, WZR-600DHP firmware Ver.1.99 and prior, WZR-D1100H firmware Ver.1.99 and prior, FS-HP-G300N firmware Ver.3.32 and prior, FS-600DHP firmware Ver.3.38 and prior, FS-R600DHP firmware Ver.3.39 and prior, and FS-G300N firmware Ver.3.13 and prior) allows remote unauthenticated attackers to obtain information such as configuration via unspecified vectors.
Affected (24)
Products: Buffalo: Bhr 4grv Firmware, Dwr Hp G300nh Firmware, Hw 450hp Zwe Firmware, Whr 300hp Firmware, Whr 300 Firmware, Whr G301n Firmware, Whr Hp G300n Firmware, Whr Hp Gn Firmware, Wpl 05g300 Firmware, Wzr 450hp Cwt Firmware, Wzr 450hp Ub Firmware, Wzr Hp Ag300h Firmware, Wzr Hp G300nh Firmware, Wzr Hp G301nh Firmware, Wzr Hp G302h Firmware, Wzr Hp G450h Firmware, Wzr 300hp Firmware, Wzr 450hp Firmware, Wzr 600dhp Firmware, Wzr D1100h Firmware, Fs Hp G300n Firmware, Fs 600dhp Firmware, Fs R600dhp Firmware, Fs G300n Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Bhr 4grv | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.84 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Dwr Hp G300nh | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Hw 450hp Zwe | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Whr 300hp | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Whr 300 | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.87 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Whr G301n | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Whr Hp G300n | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.87 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Whr Hp Gn | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.88 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wpl 05g300 | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wzr 450hp Cwt | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wzr 450hp Ub | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.76 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wzr Hp Ag300h | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.84 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wzr Hp G300nh | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.84 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wzr Hp G301nh | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.86 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wzr Hp G302h | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.90 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wzr Hp G450h | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wzr 300hp | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wzr 450hp | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wzr 600dhp | All versions |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.00 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Wzr D1100h | All versions |
Configuration U
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.33 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Fs Hp G300n | All versions |
Configuration V
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.40 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Fs 600dhp | All versions |
Configuration W
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.40 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Fs R600dhp | All versions |
Configuration X
| Vulnerable Software | Affected Versions |
|---|---|
| Before 3.14 |
| Running on/with | Platform Versions |
|---|---|
Buffalo Fs G300n | All versions |
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.