Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-1134

Опубликовано: 22 янв. 2016
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WHR-600D devices with firmware 1.90 and earlier, WMR-300 devices with firmware 1.90 and earlier, WMR-433 devices with firmware 1.01 and earlier, and WSR-1166DHP devices with firmware 1.01 and earlier allows remote attackers to hijack the authentication of arbitrary users.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:h:buffalotech:whr-1166dhp:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:whr-1166dhp_firmware:*:*:*:*:*:*:*:*
Версия до 1.90 (включая)
Конфигурация 2

Одновременно

cpe:2.3:h:buffalotech:whr-300hp2:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:whr-300hp2_firmware:*:*:*:*:*:*:*:*
Версия до 1.90 (включая)
Конфигурация 3

Одновременно

cpe:2.3:h:buffalotech:wmr-300:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:wmr-300_firmware:*:*:*:*:*:*:*:*
Версия до 1.90 (включая)
Конфигурация 4

Одновременно

cpe:2.3:h:buffalotech:bhr-4grv2:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:bhr-4grv2_firmware:*:*:*:*:*:*:*:*
Версия до 1.04 (включая)
Конфигурация 5

Одновременно

cpe:2.3:h:buffalotech:wex-300:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:wex-300_firmware:*:*:*:*:*:*:*:*
Версия до 1.90 (включая)
Конфигурация 6

Одновременно

cpe:2.3:h:buffalotech:whr-600d:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:whr-600d_firmware:*:*:*:*:*:*:*:*
Версия до 1.90 (включая)
Конфигурация 7

Одновременно

cpe:2.3:h:buffalotech:wmr-433:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:wmr-433_firmware:*:*:*:*:*:*:*:*
Версия до 1.01 (включая)
Конфигурация 8

Одновременно

cpe:2.3:h:buffalotech:wsr-1166dhp:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalotech:wsr-1166dhp_firmware:*:*:*:*:*:*:*:*
Версия до 1.01 (включая)

EPSS

Процентиль: 29%
0.00103
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WHR-600D devices with firmware 1.90 and earlier, WMR-300 devices with firmware 1.90 and earlier, WMR-433 devices with firmware 1.01 and earlier, and WSR-1166DHP devices with firmware 1.01 and earlier allows remote attackers to hijack the authentication of arbitrary users.

EPSS

Процентиль: 29%
0.00103
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352