Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify settings, as demonstrated by changing the login password.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://buffalo.jp/support_s/20080808/csrf.html - | |
References | () http://jvn.jp/en/jp/JVN50505257/index.html - |
Information
Published : 2011-05-09 19:55
Updated : 2024-11-21 01:26
NVD link : CVE-2011-1324
Mitre link : CVE-2011-1324
CVE.ORG link : CVE-2011-1324
JSON object : View
Products Affected
buffalotech
- whr-g_firmware
- wzr-g144nh
- wzr-ampg300nh_firmware
- as-100
- whr-hp-ampg
- whr-amg54_firmware
- wer-am54g54
- bhr-4rv
- wer-amg54
- wer-am54g54_firmware
- whr-g54s_firmware
- whr-g54s
- wzr-ampg144nh_firmware
- wzr-g144nh_firmware
- wer-amg54_firmware
- wer-ag54
- wzr-ampg144nh
- wzr-ampg300nh
- whr-ampg
- whr-hp-g_firmware
- wer-a54g54_firmware
- whr-hp-ampg_firmware
- wer-a54g54
- bbr-4mg
- whr-am54g54_firmware
- bbr-4hg_firmware
- wzr-g144n_firmware
- whr-hp-g54
- fs-g54
- bbr-4hg
- whr-g
- whr-amg54
- wzr-g144n
- wzr2-g300n_firmware
- bhr-4rv_firmware
- wer-ag54_firmware
- whr-am54g54
- wzr2-g300n
- whr-ampg_firmware
- bbr-4mg_firmware
- whr-hp-g54_firmware
- fs-g54_firmware
- whr-hp-g
CWE
CWE-352
Cross-Site Request Forgery (CSRF)