Buffalo Technology manufactures a moderately broad range of consumer and small-business networking equipment, including wireless access points, routers, and storage devices, that are widely deployed in distributed environments. Its vulnerability disclosures cluster consistently around web-interface and access-control weaknesses—CSRF, path traversal, cross-site scripting, improper access control, and input validation flaws—that are characteristic of embedded device firmware with web management surfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Buffalotech over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-7824HIGH Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the debug option via unspecified vectors. | Jun 9, 2017 | 8.8 | 26 | NO | NO |
CVE-2016-7822HIGH Cross-site request forgery (CSRF) vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows remote attackers to hijack the authentication of a logge | Jun 9, 2017 | 8.8 | 26 | NO | NO |
CVE-2016-1134HIGH Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices wit | Jan 22, 2016 | 8.8 | 25 | NO | NO |
CVE-2016-7825MEDIUM Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted | Jun 9, 2017 | 6.5 | 21 | NO | NO |
CVE-2014-9284HIGH The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 and earlier, WEX-300 1.60 and earlier, a | Jun 9, 2015 | 7.7 | 20 | NO | NO |
CVE-2011-1324MEDIUM Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 rou | May 9, 2011 | 5.8 | 19 | NO | NO |
CVE-2016-7826MEDIUM Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted | Jun 9, 2017 | 6.5 | 18 | NO | NO |
CVE-2016-7821MEDIUM Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the management screen via unspecified vectors. | Jun 9, 2017 | 6.5 | 18 | NO | NO |
CVE-2015-8262MEDIUM Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote a | Dec 27, 2015 | 6.8 | 18 | NO | NO |
CVE-2016-1135MEDIUM Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmw | Jan 22, 2016 | 6.1 | 17 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Buffalotech.
Media articles that mention a CVE ID that affects a product developed by Buffalotech — matched by CVE ID, not by vendor name.