← Back

Buffalo

buffalo

56 CVEs • 361 products

Products (361)

Click to collapse
Toggle
Open Xdmod
open_xdmod

CVEs (56)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Buffalo
1Ts5600d1206 Firmware
Nov 21, 2024
Nov 26, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Incorrect access control in get_portal_info in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to determine sensitive device information via an unauthenticated POST request.
1Buffalo
1Ts5600d1206 Firmware
Nov 21, 2024
Nov 26, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
System command injection in User.create method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute system commands via the "name" parameter.
1Buffalo
1Wzr 1750dhp2 Firmware
Nov 21, 2024
Apr 9, 2018
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
1Buffalo
1Wzr 1750dhp2 Firmware
Nov 21, 2024
Apr 9, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Buffer overflow in Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary code via a specially crafted file.
1Buffalo
1Wzr 1750dhp2 Firmware
Nov 21, 2024
Apr 9, 2018
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors.
1Buffalo
1Wxr 1900dhp2 Firmware
Nov 21, 2024
Mar 9, 2018
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
1Buffalo
1Wxr 1900dhp2 Firmware
Nov 21, 2024
Mar 9, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Buffer overflow in Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary code via a specially crafted file.
1Buffalo
1Wxr 1900dhp2 Firmware
Nov 21, 2024
Mar 9, 2018
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors.
1Buffalo
2Bbr 4hg Firmware
Bbr 4mg Firmware
May 13, 2026
Dec 8, 2017
N/A· v4
4.5 MEDIUM· v3
5.5 MEDIUM· v2
Input validation issue in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to cause the device to become unresponsive via unspecified vectors.
1Buffalo
2Bbr 4hg Firmware
Bbr 4mg Firmware
May 13, 2026
Dec 8, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
1Buffalo
1Wcr 1166ds Firmware
May 13, 2026
Aug 18, 2017
N/A· v4
6.8 MEDIUM· v3
7.7 HIGH· v2
Buffalo WCR-1166DS devices with firmware 1.30 and earlier allow an attacker to execute arbitrary OS commands via unspecified vectors.
1Buffalo
2Wmr 433 Firmware
Wmr 433w Firmware
May 13, 2026
Jul 22, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Buffalo
2Wmr 433 Firmware
Wmr 433w Firmware
May 13, 2026
Jul 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vect...Show more
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.Show less
1Buffalo
2Wapm 1166d Firmware
Wapm Apg600h Firmware
May 13, 2026
Jul 22, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and access the configuration interface via unspecified vectors.
1Buffalo
34Bhr 4grv Firmware
Dwr Hp G300nh FirmwareFs 600dhp Firmware+31 more
May 6, 2026
Jun 19, 2016
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices allow remote attackers to discover credentials and other sensitive information via unspecified vectors.
1Buffalo
6Wzr 600dhp2 Firmware
Wzr 600dhp3 FirmwareWzr 900dhp2 Firmware+3 more
May 6, 2026
Jun 19, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Directory traversal vulnerability on BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices with firmware 2.16 and earlier allows remote attackers to read arbitrary files via unspecified vecto...Show more
Directory traversal vulnerability on BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices with firmware 2.16 and earlier allows remote attackers to read arbitrary files via unspecified vectors.Show less