CVE-2016-1134

Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WHR-600D devices with firmware 1.90 and earlier, WMR-300 devices with firmware 1.90 and earlier, WMR-433 devices with firmware 1.01 and earlier, and WSR-1166DHP devices with firmware 1.01 and earlier allows remote attackers to hijack the authentication of arbitrary users.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:h:buffalotech:whr-1166dhp:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:whr-1166dhp_firmware:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:h:buffalotech:whr-300hp2:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:whr-300hp2_firmware:*:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:h:buffalotech:wmr-300:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:wmr-300_firmware:*:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:h:buffalotech:bhr-4grv2:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:bhr-4grv2_firmware:*:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:h:buffalotech:wex-300:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:wex-300_firmware:*:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:h:buffalotech:whr-600d:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:whr-600d_firmware:*:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:h:buffalotech:wmr-433:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:wmr-433_firmware:*:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:h:buffalotech:wsr-1166dhp:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:wsr-1166dhp_firmware:*:*:*:*:*:*:*:*

History

21 Nov 2024, 02:45

Type Values Removed Values Added
References () http://jvn.jp/en/jp/JVN09268287/index.html - Vendor Advisory () http://jvn.jp/en/jp/JVN09268287/index.html - Vendor Advisory
References () http://jvndb.jvn.jp/jvndb/JVNDB-2016-000005 - Vendor Advisory () http://jvndb.jvn.jp/jvndb/JVNDB-2016-000005 - Vendor Advisory

Information

Published : 2016-01-22 11:59

Updated : 2024-11-21 02:45


NVD link : CVE-2016-1134

Mitre link : CVE-2016-1134

CVE.ORG link : CVE-2016-1134


JSON object : View

Products Affected

buffalotech

  • whr-1166dhp_firmware
  • whr-600d
  • whr-1166dhp
  • wmr-433_firmware
  • wex-300
  • wsr-1166dhp
  • whr-300hp2_firmware
  • wmr-300_firmware
  • bhr-4grv2
  • bhr-4grv2_firmware
  • whr-600d_firmware
  • wmr-433
  • wmr-300
  • wsr-1166dhp_firmware
  • wex-300_firmware
  • whr-300hp2
CWE
CWE-352

Cross-Site Request Forgery (CSRF)