Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify settings, as demonstrated by changing the login password.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2011-05-09 19:55
Updated : 2024-02-04 17:54
NVD link : CVE-2011-1324
Mitre link : CVE-2011-1324
CVE.ORG link : CVE-2011-1324
JSON object : View
Products Affected
buffalotech
- whr-g54s
- whr-hp-g_firmware
- wzr-ampg300nh_firmware
- wzr-g144n
- bhr-4rv_firmware
- wzr-ampg144nh
- bhr-4rv
- whr-g_firmware
- wer-a54g54_firmware
- fs-g54_firmware
- wer-amg54_firmware
- whr-hp-g54_firmware
- whr-am54g54
- wzr2-g300n_firmware
- wzr2-g300n
- whr-hp-ampg
- wzr-g144nh
- whr-g
- wer-amg54
- wer-ag54
- wer-ag54_firmware
- whr-amg54_firmware
- wzr-g144n_firmware
- wzr-ampg144nh_firmware
- fs-g54
- whr-hp-ampg_firmware
- bbr-4hg_firmware
- bbr-4mg_firmware
- whr-am54g54_firmware
- whr-ampg_firmware
- wer-am54g54
- wzr-ampg300nh
- bbr-4hg
- wzr-g144nh_firmware
- bbr-4mg
- whr-hp-g54
- as-100
- whr-ampg
- wer-a54g54
- whr-amg54
- wer-am54g54_firmware
- whr-g54s_firmware
- whr-hp-g
CWE
CWE-352
Cross-Site Request Forgery (CSRF)