VYPR
Medium severity6.1NVD Advisory· Published Dec 8, 2017· Updated May 13, 2026

CVE-2017-10896

CVE-2017-10896

Description

Cross-site scripting vulnerability in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

Affected products

4
  • cpe:2.3:o:buffalo:bbr-4hg_firmware:*:*:*:*:*:*:*:*
    Range: >=1.00,<=1.48
  • cpe:2.3:o:buffalo:bbr-4mg_firmware:*:*:*:*:*:*:*:*
    Range: >=1.00,<=1.48
  • BUFFALO INC./BBR-4HGv5
    Range: firmware 1.00 to 1.48
  • BUFFALO INC./BBR-4MGv5
    Range: firmware 1.00 to 1.48

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.