CVE-2025-46413 describes a password hash vulnerability in BUFFALO WSR-1800AX4 series Wi-Fi routers, where insufficient computational effort in the password hash allows attackers to potentially obtain the WPS PIN or Wi-Fi password when WPS is enabled. This vulnerability has a CVSS score of 4.3 (MEDIUM), indicating a low-impact attack that can be executed with low complexity over an adjacent network. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| BUFFALO INC. | WSR-1800AX4 | prior to Ver.1.09CNA affected | |
| BUFFALO INC. | WSR-1800AX4-KH | prior to Ver.1.19CNA affected | |
| BUFFALO INC. | WSR-1800AX4B | prior to Ver.1.11CNA affected | |
| BUFFALO INC. | WSR-1800AX4S | prior to Ver.1.11CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.