← Back

CVE-2022-34840

nvd nist
Published: Dec 7, 2022Modified: Apr 23, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device. The affected products/versions are as follows: WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, and WZR-D1100H firmware Ver. 2.00 and earlier.

Affected (9)

9 products
Wzr 300hp Firmware
Wzr 450hp Firmware
Wzr 600dhp Firmware
Wzr 900dhp Firmware
Hw 450hp Zwe Firmware
Wzr 450hp Cwt Firmware
Wzr 450hp Ub Firmware
Wzr 600dhp2 Firmware
Wzr D1100h Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.00
Running on/withPlatform Versions
Buffalo
Wzr 300hp
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.00
Running on/withPlatform Versions
Buffalo
Wzr 450hp
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.00
Running on/withPlatform Versions
Buffalo
Wzr 600dhp
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.15
Running on/withPlatform Versions
Buffalo
Wzr 900dhp
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.00
Running on/withPlatform Versions
Buffalo
Hw 450hp Zwe
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.00
Running on/withPlatform Versions
Buffalo
Wzr 450hp Cwt
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.00
Running on/withPlatform Versions
Buffalo
Wzr 450hp Ub
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.15
Running on/withPlatform Versions
Buffalo
Wzr 600dhp2
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 2.00
Running on/withPlatform Versions
Buffalo
Wzr D1100h
All versions

References (4)

Source: vultures@jpcert.or.jp
Third Party Advisory
Source: vultures@jpcert.or.jp
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.