Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify settings, as demonstrated by changing the login password.
The web application does not, or can not, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bbr-4hg_firmware | Buffalotech | 1.02 (including) | 1.02 (including) |
Bbr-4hg_firmware | Buffalotech | 1.04 (including) | 1.04 (including) |
Bbr-4hg_firmware | Buffalotech | 1.04-beta (including) | 1.04-beta (including) |
Bbr-4hg_firmware | Buffalotech | 1.10 (including) | 1.10 (including) |
Bbr-4hg_firmware | Buffalotech | 1.10-beta (including) | 1.10-beta (including) |
Bbr-4hg_firmware | Buffalotech | 1.11-beta (including) | 1.11-beta (including) |
Bbr-4hg_firmware | Buffalotech | 1.12 (including) | 1.12 (including) |
Bbr-4hg_firmware | Buffalotech | 1.20 (including) | 1.20 (including) |
Bbr-4hg_firmware | Buffalotech | 1.20-beta (including) | 1.20-beta (including) |
Bbr-4hg_firmware | Buffalotech | 1.30 (including) | 1.30 (including) |
Bbr-4hg_firmware | Buffalotech | 1.30-beta (including) | 1.30-beta (including) |
Bbr-4hg_firmware | Buffalotech | 1.31 (including) | 1.31 (including) |
Bbr-4hg_firmware | Buffalotech | 1.32 (including) | 1.32 (including) |
Bbr-4hg_firmware | Buffalotech | 1.32-beta (including) | 1.32-beta (including) |
Bbr-4hg_firmware | Buffalotech | 1.33-beta (including) | 1.33-beta (including) |
Bbr-4mg_firmware | Buffalotech | 1.00 (including) | 1.00 (including) |
Bbr-4mg_firmware | Buffalotech | 1.01-beta (including) | 1.01-beta (including) |
Bbr-4mg_firmware | Buffalotech | 1.03 (including) | 1.03 (including) |
Bbr-4mg_firmware | Buffalotech | 1.04 (including) | 1.04 (including) |
Bbr-4mg_firmware | Buffalotech | 1.04-beta (including) | 1.04-beta (including) |
Bbr-4mg_firmware | Buffalotech | 1.10 (including) | 1.10 (including) |
Bbr-4mg_firmware | Buffalotech | 1.10-beta (including) | 1.10-beta (including) |
Bbr-4mg_firmware | Buffalotech | 1.11-beta (including) | 1.11-beta (including) |
Bbr-4mg_firmware | Buffalotech | 1.12 (including) | 1.12 (including) |
Bbr-4mg_firmware | Buffalotech | 1.20 (including) | 1.20 (including) |
Bbr-4mg_firmware | Buffalotech | 1.20-beta (including) | 1.20-beta (including) |
Bbr-4mg_firmware | Buffalotech | 1.30 (including) | 1.30 (including) |
Bbr-4mg_firmware | Buffalotech | 1.30-beta (including) | 1.30-beta (including) |
Bbr-4mg_firmware | Buffalotech | 1.31 (including) | 1.31 (including) |
Bbr-4mg_firmware | Buffalotech | 1.32 (including) | 1.32 (including) |
Bbr-4mg_firmware | Buffalotech | 1.32-beta (including) | 1.32-beta (including) |
Bbr-4mg_firmware | Buffalotech | 1.33 (including) | 1.33 (including) |
Bbr-4mg_firmware | Buffalotech | 1.33-beta (including) | 1.33-beta (including) |
Bhr-4rv_firmware | Buffalotech | 2.31 (including) | 2.31 (including) |
Bhr-4rv_firmware | Buffalotech | 2.32-prebeta (including) | 2.32-prebeta (including) |
Bhr-4rv_firmware | Buffalotech | 2.33-prebeta (including) | 2.33-prebeta (including) |
Bhr-4rv_firmware | Buffalotech | 2.42 (including) | 2.42 (including) |
Bhr-4rv_firmware | Buffalotech | 2.46 (including) | 2.46 (including) |
Bhr-4rv_firmware | Buffalotech | 2.48 (including) | 2.48 (including) |
Fs-g54_firmware | Buffalotech | 2.07 (including) | 2.07 (including) |
Wer-a54g54_firmware | Buffalotech | 1.00 (including) | 1.00 (including) |
Wer-a54g54_firmware | Buffalotech | 1.01-beta (including) | 1.01-beta (including) |
Wer-a54g54_firmware | Buffalotech | 1.02 (including) | 1.02 (including) |
Wer-a54g54_firmware | Buffalotech | 1.03 (including) | 1.03 (including) |
Wer-a54g54_firmware | Buffalotech | 1.10 (including) | 1.10 (including) |
Wer-a54g54_firmware | Buffalotech | 1.12 (including) | 1.12 (including) |
Wer-a54g54_firmware | Buffalotech | 1.12-beta (including) | 1.12-beta (including) |
Wer-a54g54_firmware | Buffalotech | 1.13 (including) | 1.13 (including) |
Wer-ag54_firmware | Buffalotech | 1.04 (including) | 1.04 (including) |
Wer-ag54_firmware | Buffalotech | 1.12 (including) | 1.12 (including) |
Wer-ag54_firmware | Buffalotech | 1.12-beta (including) | 1.12-beta (including) |
Wer-am54g54_firmware | Buffalotech | 1.11 (including) | 1.11 (including) |
Wer-am54g54_firmware | Buffalotech | 1.12 (including) | 1.12 (including) |
Wer-am54g54_firmware | Buffalotech | 1.12-beta (including) | 1.12-beta (including) |
Wer-am54g54_firmware | Buffalotech | 1.13 (including) | 1.13 (including) |
Wer-am54g54_firmware | Buffalotech | 1.14 (including) | 1.14 (including) |
Wer-amg54_firmware | Buffalotech | 1.11 (including) | 1.11 (including) |
Wer-amg54_firmware | Buffalotech | 1.12 (including) | 1.12 (including) |
Wer-amg54_firmware | Buffalotech | 1.14 (including) | 1.14 (including) |
Whr-am54g54_firmware | Buffalotech | 1.30 (including) | 1.30 (including) |
Whr-am54g54_firmware | Buffalotech | 1.38 (including) | 1.38 (including) |
Whr-am54g54_firmware | Buffalotech | 1.40 (including) | 1.40 (including) |
Whr-am54g54_firmware | Buffalotech | 1.42 (including) | 1.42 (including) |
Whr-amg54_firmware | Buffalotech | 1.31 (including) | 1.31 (including) |
Whr-amg54_firmware | Buffalotech | 1.38 (including) | 1.38 (including) |
Whr-amg54_firmware | Buffalotech | 1.40 (including) | 1.40 (including) |
Whr-amg54_firmware | Buffalotech | 1.42 (including) | 1.42 (including) |
Whr-ampg_firmware | Buffalotech | 1.46 (including) | 1.46 (including) |
Whr-g_firmware | Buffalotech | 1.46 (including) | 1.46 (including) |
Whr-g54s_firmware | Buffalotech | 1.20 (including) | 1.20 (including) |
Whr-g54s_firmware | Buffalotech | 1.21 (including) | 1.21 (including) |
Whr-g54s_firmware | Buffalotech | 1.23 (including) | 1.23 (including) |
Whr-g54s_firmware | Buffalotech | 1.38 (including) | 1.38 (including) |
Whr-g54s_firmware | Buffalotech | 1.40 (including) | 1.40 (including) |
Whr-g54s_firmware | Buffalotech | 1.42 (including) | 1.42 (including) |
Whr-hp-ampg_firmware | Buffalotech | 1.32 (including) | 1.32 (including) |
Whr-hp-g_firmware | Buffalotech | 1.46 (including) | 1.46 (including) |
Whr-hp-g54_firmware | Buffalotech | 1.20 (including) | 1.20 (including) |
Whr-hp-g54_firmware | Buffalotech | 1.21 (including) | 1.21 (including) |
Whr-hp-g54_firmware | Buffalotech | 1.23 (including) | 1.23 (including) |
Whr-hp-g54_firmware | Buffalotech | 1.38 (including) | 1.38 (including) |
Whr-hp-g54_firmware | Buffalotech | 1.40 (including) | 1.40 (including) |
Whr-hp-g54_firmware | Buffalotech | 1.42 (including) | 1.42 (including) |
Wzr-ampg144nh_firmware | Buffalotech | 1.47 (including) | 1.47 (including) |
Wzr-ampg144nh_firmware | Buffalotech | 1.48-beta (including) | 1.48-beta (including) |
Wzr-ampg300nh_firmware | Buffalotech | 1.48 (including) | 1.48 (including) |
Wzr-g144n_firmware | Buffalotech | 1.45 (including) | 1.45 (including) |
Wzr-g144n_firmware | Buffalotech | 1.46-beta (including) | 1.46-beta (including) |
Wzr-g144n_firmware | Buffalotech | 1.47 (including) | 1.47 (including) |
Wzr-g144n_firmware | Buffalotech | 1.47-beta (including) | 1.47-beta (including) |
Wzr-g144nh_firmware | Buffalotech | 1.45 (including) | 1.45 (including) |
Wzr-g144nh_firmware | Buffalotech | 1.47 (including) | 1.47 (including) |
Wzr-g144nh_firmware | Buffalotech | 1.47-beta (including) | 1.47-beta (including) |
Wzr-g144nh_firmware | Buffalotech | 1.48 (including) | 1.48 (including) |
Wzr2-g300n_firmware | Buffalotech | 1.48 (including) | 1.48 (including) |
Wzr2-g300n_firmware | Buffalotech | 1.50-beta (including) | 1.50-beta (including) |
As-100 | Buffalotech | * | * |
Bbr-4hg | Buffalotech | * | * |
Bbr-4mg | Buffalotech | * | * |
Bhr-4rv | Buffalotech | * | * |
Fs-g54 | Buffalotech | * | * |
Wer-a54g54 | Buffalotech | * | * |
Wer-ag54 | Buffalotech | * | * |
Wer-am54g54 | Buffalotech | * | * |
Wer-amg54 | Buffalotech | * | * |
Whr-am54g54 | Buffalotech | * | * |
Whr-amg54 | Buffalotech | * | * |
Whr-ampg | Buffalotech | * | * |
Whr-g | Buffalotech | * | * |
Whr-g54s | Buffalotech | * | * |
Whr-hp-ampg | Buffalotech | * | * |
Whr-hp-g | Buffalotech | * | * |
Whr-hp-g54 | Buffalotech | * | * |
Wzr-ampg144nh | Buffalotech | * | * |
Wzr-ampg300nh | Buffalotech | * | * |
Wzr-g144n | Buffalotech | * | * |
Wzr-g144nh | Buffalotech | * | * |
Wzr2-g300n | Buffalotech | * | * |