Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Buffalotech

First CVE: Sep 11, 2007Active for: 19 yearsTotal CVEs: 12
13.5
VTI Score
Low

Buffalo Technology manufactures a moderately broad range of consumer and small-business networking equipment, including wireless access points, routers, and storage devices, that are widely deployed in distributed environments. Its vulnerability disclosures cluster consistently around web-interface and access-control weaknesses—CSRF, path traversal, cross-site scripting, improper access control, and input validation flaws—that are characteristic of embedded device firmware with web management surfaces. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
12
Total CVEs
More Total CVEs than 93% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Buffalotech over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 11, 2007
18 years ago
Most Recent CVE
Jun 9, 2017
3,332 days ago

Products(66 total)

Top CVEs

Signals from CVEs in this vendor scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2016-7824HIGH
Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction to enable the debug option via unspecified vectors.
Jun 9, 20178.826NONO
CVE-2016-7822HIGH
Cross-site request forgery (CSRF) vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows remote attackers to hijack the authentication of a logge
Jun 9, 20178.826NONO
CVE-2016-1134HIGH
Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices wit
Jan 22, 20168.825NONO
CVE-2016-7825MEDIUM
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted
Jun 9, 20176.521NONO
CVE-2014-9284HIGH
The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 and earlier, WEX-300 1.60 and earlier, a
Jun 9, 20157.720NONO
CVE-2011-1324MEDIUM
Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 rou
May 9, 20115.819NONO
CVE-2016-7826MEDIUM
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted
Jun 9, 20176.518NONO
CVE-2016-7821MEDIUM
Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the management screen via unspecified vectors.
Jun 9, 20176.518NONO
CVE-2015-8262MEDIUM
Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote a
Dec 27, 20156.818NONO
CVE-2016-1135MEDIUM
Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmw
Jan 22, 20166.117NONO
View all 12 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products12 CVEs
67%
33%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network8 (66.7%)
Unknown3 (25.0%)
Physical0 (0.0%)
Adjacent Network1 (8.3%)
Attack Complexity
Low8 (66.7%)
High1 (8.3%)
Unknown3 (25.0%)
User Interaction
None4 (33.3%)
Unknown3 (25.0%)
Required5 (41.7%)
Privileges Required
Low3 (25.0%)
High1 (8.3%)
None5 (41.7%)
Unknown3 (25.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Buffalotech.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Buffalotech — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Buffalotech's Products

View all 3 CNAs →

Top CWEs