VYPR

Vendor CVEs

Buffalotech

All CVEs

81 total · sorted by risk
  • CVE-2025-66954MedApr 20, 2026
    risk 0.42cvss 6.5epss 0.00

    A vulnerability exists in the Buffalo Link Station version 1.85-0.01 that allows unauthenticated or guest-level users to enumerate valid usernames and their associated privilege roles. The issue is triggered by modifying a parameter within requests sent to the /nasapi endpoint.

  • CVE-2023-51363MedDec 26, 2023
    risk 0.42cvss 6.5epss 0.00

    VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's web management page to obtain sensitive information.

  • CVE-2022-34840MedDec 7, 2022
    risk 0.42cvss 6.5epss 0.00

    Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device. The affected products/versions are as follows: WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00…

  • CVE-2018-13322MedNov 26, 2018
    risk 0.42cvss 6.5epss 0.01

    Directory traversal in list_folders method in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to list directory contents via the "path" parameter.

  • CVE-2016-7826MedJun 9, 2017
    risk 0.42cvss 6.5epss 0.02

    Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted POST requests.

  • CVE-2016-7825MedJun 9, 2017
    risk 0.42cvss 6.5epss 0.02

    Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted commands.

  • CVE-2016-7821MedJun 9, 2017
    risk 0.42cvss 6.5epss 0.02

    Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against the management screen via unspecified vectors.

  • CVE-2016-4816MedJun 19, 2016
    risk 0.42cvss 6.5epss 0.01

    BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices allow remote attackers to discover credentials and other sensitive information via unspecified vectors.

  • CVE-2020-5606MedSep 18, 2020
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in WHR-G54S firmware 1.43 and earlier allows remote attackers to inject arbitrary script via a specially crafted page.

  • CVE-2018-16960MedMay 2, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/login.php has Reflected XSS via the xd_user_formal_name parameter.

  • CVE-2018-13323MedNov 26, 2018
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting in detail.html in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to execute JavaScript via the "username" cookie.

  • CVE-2017-10896MedDec 8, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2017-2274MedJul 22, 2017
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2016-1135MedJan 22, 2016
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WHR-600D devices with…

  • CVE-2024-44072MedSep 10, 2024
    risk 0.37cvss 5.7epss 0.01

    OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may…

  • CVE-2026-45778MedJun 5, 2026
    risk 0.35cvss 5.4epss 0.00

    OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious JavaScript into their Open XDMoD user profile and abuse the password reset functionality to email a link to an HTML page, which when…

  • CVE-2023-24464MedApr 11, 2023
    risk 0.35cvss 5.4epss 0.00

    Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web management console of the product to execute arbitrary JavaScript on a legitimate user's web browser. The affected products and versions are as follows: BS-GS2008…

  • CVE-2026-33366MedMar 27, 2026
    risk 0.34cvss 5.3epss 0.00

    Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product without authentication.

  • CVE-2026-29516MedMar 16, 2026
    risk 0.32cvss 4.9epss 0.01

    Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnerability that allows authenticated attackers to read the /etc/shadow file by uploading and executing a PHP file through the webserver. Attackers can exploit…

  • CVE-2023-46711MedDec 26, 2023
    risk 0.30cvss 4.6epss 0.00

    VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the password of a specific product user.

  • CVE-2017-10897MedDec 8, 2017
    risk 0.29cvss 4.5epss 0.00

    Input validation issue in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to cause the device to become unresponsive via unspecified vectors.

  • CVE-2026-45776MedJun 5, 2026
    risk 0.28cvss 4.3epss 0.00

    OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allows an attacker to submit a crafted HTTPS POST request that sets a session variable used for authorization decisions. If an…

  • CVE-2025-46413MedNov 7, 2025
    risk 0.28cvss 4.3epss 0.00

    Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. When WPS is enabled, PIN code and/or Wi-Fi password may be obtained by an attacker.

  • CVE-2021-20730MedJun 9, 2021
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allows an attacker to obtain configuration information via unspecified vectors.

  • CVE-2021-3511MedApr 28, 2021
    risk 0.28cvss 4.3epss 0.01

    Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP firmware Ver.1.99 and prior, WHR-300…

  • CVE-2020-5605MedSep 18, 2020
    risk 0.28cvss 4.3epss 0.01

    Directory traversal vulnerability in WHR-G54S firmware 1.43 and earlier allows an attacker to access sensitive information such as setting values via unspecified vectors.

  • CVE-2016-7823MedJun 9, 2017
    risk 0.28cvss 4.3epss 0.00

    Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2024-26023MedApr 15, 2024
    risk 0.27cvss 4.2epss 0.01

    OS command injection vulnerability in BUFFALO wireless LAN routers allows a logged-in user to execute arbitrary OS commands.

  • CVE-2014-9284Jun 9, 2015
    risk 0.00cvss epss 0.01

    The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier, WMR-300 1.60 and earlier, WEX-300 1.60 and earlier, and BHR-4GRV2 1.04 and earlier routers allow remote authenticated users to execute arbitrary OS…

  • CVE-2011-1324May 9, 2011
    risk 0.00cvss epss 0.00

    Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of…

  • CVE-2007-4822Sep 11, 2007
    risk 0.00cvss epss 0.01

    Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attackers to make configuration changes as an administrator via HTTP requests to certain HTML pages in the res parameter with an inp req parameter…

Page 2 of 2