Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the device
Published Dec 7, 2022
8.8
HIGHCVSS 3.1
EPSS 0.35%
Description
Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the device. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and earlier, WHR-HP-GN firmware Ver. 1.87 and earlier, WPL-05G300 firmware Ver. 1.88 and earlier, WRM-D2133HP firmware Ver. 2.85 and earlier, WRM-D2133HS firmware Ver. 2.96 and earlier, WTR-M2133HP firmware Ver. 2.85 and earlier, WTR-M2133HS firmware Ver. 2.96 and earlier, WXR-1900DHP firmware Ver. 2.50 and earlier, WXR-1900DHP2 firmware Ver. 2.59 and earlier, WXR-1900DHP3 firmware Ver. 2.63 and earlier, WXR-5950AX12 firmware Ver. 3.40 and earlier, WXR-6000AX12B firmware Ver. 3.40 and earlier, WXR-6000AX12S firmware Ver. 3.40 and earlier, WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, WZR-1750DHP2 firmware Ver. 2.31 and earlier, WZR-HP-AG300H firmware Ver. 1.76 and earlier, WZR-HP-G302H firmware Ver. 1.86 and earlier, WEM-1266 firmware Ver. 2.85 and earlier, WEM-1266WP firmware Ver. 2.85 and earlier, WLAE-AG300N firmware Ver. 1.86 and earlier, FS-600DHP firmware Ver. 3.40 and earlier, FS-G300N firmware Ver. 3.14 and earlier, FS-HP-G300N firmware Ver. 3.33 and earlier, FS-R600DHP firmware Ver. 3.40 and earlier, BHR-4GRV firmware Ver. 2.00 and earlier, DWR-HP-G300NH firmware Ver. 1.84 and earlier, DWR-PG firmware Ver. 1.83 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WER-A54G54 firmware Ver. 1.43 and earlier, WER-AG54 firmware Ver. 1.43 and earlier, WER-AM54G54 firmware Ver. 1.43 and earlier, WER-AMG54 firmware Ver. 1.43 and earlier, WHR-300 firmware Ver. 2.00 and earlier, WHR-300HP firmware Ver. 2.00 and earlier, WHR-AM54G54 firmware Ver. 1.43 and earlier, WHR-AMG54 firmware Ver. 1.43 and earlier, WHR-AMPG firmware Ver. 1.52 and earlier, WHR-G firmware Ver. 1.49 and earlier, WHR-G300N firmware Ver. 1.65 and earlier, WHR-G301N firmware Ver. 1.87 and earlier, WHR-G54S firmware Ver. 1.43 and earlier, WHR-G54S-NI firmware Ver. 1.24 and earlier, WHR-HP-AMPG firmware Ver. 1.43 and earlier, WHR-HP-G firmware Ver. 1.49 and earlier, WHR-HP-G54 firmware Ver. 1.43 and earlier, WLI-H4-D600 firmware Ver. 1.88 and earlier, WS024BF firmware Ver. 1.60 and earlier, WS024BF-NW firmware Ver. 1.60 and earlier, WXR-1750DHP firmware Ver. 2.60 and earlier, WXR-1750DHP2 firmware Ver. 2.60 and earlier, WZR-1166DHP firmware Ver. 2.18 and earlier, WZR-1166DHP2 firmware Ver. 2.18 and earlier, WZR-1750DHP firmware Ver. 2.30 and earlier, WZR2-G300N firmware Ver. 1.55 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, WZR-600DHP3 firmware Ver. 2.19 and earlier, WZR-900DHP2 firmware Ver. 2.19 and earlier, WZR-AGL300NH firmware Ver. 1.55 and earlier, WZR-AMPG144NH firmware Ver. 1.49 and earlier, WZR-AMPG300NH firmware Ver. 1.51 and earlier, WZR-D1100H firmware Ver. 2.00 and earlier, WZR-G144N firmware Ver. 1.48 and earlier, WZR-G144NH firmware Ver. 1.48 and earlier, WZR-HP-G300NH firmware Ver. 1.84 and earlier, WZR-HP-G301NH firmware Ver. 1.84 and earlier, WZR-HP-G450H firmware Ver. 1.90 and earlier, WZR-S1750DHP firmware Ver. 2.32 and earlier, WZR-S600DHP firmware Ver. 2.19 and earlier, and WZR-S900DHP firmware Ver. 2.19 and earlier.
Affected products
-
- Version A wide range of products is affected. For the specific products/versions information, see the URLs provided by the vendor and JVN which are listed in [Reference] section.StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Buffalo Inc. | Buffalo network devices | n/a |
|
Configuration 1
- ≤ 1.87
Configuration 2
- ≤ 2.00
Running on/with
- n/a
Configuration 3
- ≤ 1.87
Configuration 4
- ≤ 1.88
Running on/with
- n/a
Configuration 5
- ≤ 2.85
Running on/with
- n/a
Configuration 6
- ≤ 2.96
Running on/with
- n/a
Configuration 7
- ≤ 2.85
Running on/with
- n/a
Configuration 8
- ≤ 2.96
Running on/with
- n/a
Configuration 9
- ≤ 2.50
Running on/with
- n/a
Configuration 10
- ≤ 2.59
Running on/with
- n/a
Configuration 11
- ≤ 2.63
Running on/with
- n/a
Configuration 12
- ≤ 3.40
Running on/with
- n/a
Configuration 13
- ≤ 3.40
Running on/with
- n/a
Configuration 14
- ≤ 3.40
Running on/with
- n/a
Configuration 15
- ≤ 2.00
Configuration 16
- ≤ 2.00
Configuration 17
- ≤ 2.00
Running on/with
- n/a
Configuration 18
- ≤ 1.15
Running on/with
- n/a
Configuration 19
- ≤ 2.31
Running on/with
- n/a
Configuration 20
- ≤ 1.76
Running on/with
- n/a
Configuration 21
- ≤ 1.86
Running on/with
- n/a
Configuration 22
- ≤ 2.85
Configuration 23
- ≤ 2.85
Running on/with
- n/a
Configuration 24
- ≤ 1.86
Running on/with
- n/a
Configuration 25
- ≤ 3.40
Configuration 26
- ≤ 3.14
Configuration 27
- ≤ 3.33
Running on/with
- n/a
Configuration 28
- ≤ 3.40
Running on/with
- n/a
Configuration 29
- ≤ 2.00
Configuration 30
- ≤ 1.84
Running on/with
- n/a
Configuration 31
- ≤ 1.83
Configuration 32
- ≤ 2.00
Running on/with
- n/a
Configuration 33
- ≤ 1.43
Running on/with
- n/a
Configuration 34
- ≤ 1.43
Configuration 35
- ≤ 1.43
Running on/with
- n/a
Configuration 36
- ≤ 1.43
Configuration 37
- ≤ 2.00
Configuration 38
- ≤ 2.00
Configuration 39
- ≤ 1.43
Running on/with
- n/a
Configuration 40
- ≤ 1.43
Configuration 41
- ≤ 1.52
Configuration 42
- ≤ 1.49
Configuration 43
- ≤ 1.65
Configuration 44
- ≤ 1.87
Configuration 45
- ≤ 1.43
Configuration 46
- ≤ 1.24
Running on/with
- n/a
Configuration 47
- ≤ 1.43
Running on/with
- n/a
Configuration 48
- ≤ 1.49
Configuration 49
- ≤ 1.43
Running on/with
- n/a
Configuration 50
- ≤ 1.88
Running on/with
- n/a
Configuration 51
- ≤ 1.60
Configuration 52
- ≤ 1.60
Running on/with
- n/a
Configuration 53
- ≤ 2.60
Running on/with
- n/a
Configuration 54
- ≤ 2.60
Running on/with
- n/a
Configuration 55
- ≤ 2.18
Running on/with
- n/a
Configuration 56
- ≤ 2.18
Running on/with
- n/a
Configuration 57
- ≤ 2.30
Running on/with
- n/a
Configuration 58
- ≤ 1.55
Running on/with
- n/a
Configuration 59
- ≤ 2.00
Running on/with
- n/a
Configuration 60
- ≤ 2.00
Running on/with
- n/a
Configuration 61
- ≤ 1.15
Running on/with
- n/a
Configuration 62
- ≤ 2.19
Running on/with
- n/a
Configuration 63
- ≤ 2.19
Running on/with
- n/a
Configuration 64
- ≤ 1.55
Running on/with
- n/a
Configuration 65
- ≤ 1.49
Running on/with
- n/a
Configuration 66
- ≤ 1.51
Running on/with
- n/a
Configuration 67
- ≤ 2.00
Running on/with
- n/a
Configuration 68
- ≤ 1.48
Configuration 69
- ≤ 1.48
Running on/with
- n/a
Configuration 70
- ≤ 1.84
Running on/with
- n/a
Configuration 71
- ≤ 1.84
Running on/with
- n/a
Configuration 72
- ≤ 1.90
Running on/with
- n/a
Configuration 73
- ≤ 2.32
Running on/with
- n/a
Configuration 74
- ≤ 2.19
Running on/with
- n/a
Configuration 75
- ≤ 2.19
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (2)
- https://jvn.jp/en/vu/JVNVU92805279/index.html Third Party Advisory
- https://www.buffalo.jp/news/detail/20221003-01.html PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://jvn.jp/en/vu/JVNVU92805279/index.html | Third Party Advisory | |
| https://www.buffalo.jp/news/detail/20221003-01.html | PatchVendor Advisory |
Change history (0)
No recorded changes yet.