CVE-2016-1134 describes a Cross-Site Request Forgery (CSRF) vulnerability affecting multiple Buffalo router models, including the BHR-4GRV2, WEX-300, and WHR-series, with specific firmware versions. This high-severity vulnerability (CVSS 8.8) allows remote attackers to hijack authenticated user sessions, potentially leading to unauthorized actions with high impact on confidentiality, integrity, and availability. While the EPSS score is low and there is no known exploit intelligence or active exploitation, the vulnerability's nature makes it a significant risk if exploited. There is no community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.90CPE matchmatch criteria | cpe:2.3:o:buffalotech:whr-1166dhp_firmware:*:*:*:*:*:*:*:* | ||
<= 1.90CPE matchmatch criteria | cpe:2.3:o:buffalotech:whr-300hp2_firmware:*:*:*:*:*:*:*:* | ||
<= 1.90CPE matchmatch criteria | cpe:2.3:o:buffalotech:wmr-300_firmware:*:*:*:*:*:*:*:* | ||
<= 1.04CPE matchmatch criteria | cpe:2.3:o:buffalotech:bhr-4grv2_firmware:*:*:*:*:*:*:*:* | ||
<= 1.90CPE matchmatch criteria | cpe:2.3:o:buffalotech:wex-300_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.