Loading HuntDB...

BUFFALO INC.

53 Products 33 CVEs

CVE Severity Distribution (All Time)

Critical
1
High
0
Medium
2
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

View all
CVE-2024-44072 MEDIUM 1 year ago

OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and se…

CVE-2024-26023 MEDIUM 1 year, 4 months ago

OS command injection vulnerability in BUFFALO wireless LAN routers allows a logged-in user to execute arbitrary OS commands.

CVE-2024-23486 CRITICAL 1 year, 4 months ago

Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access…

CVE-2023-51363 UNKNOWN 1 year, 8 months ago

VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's web management page to obtain…

CVE-2023-46711 UNKNOWN 1 year, 8 months ago

VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the password of a specific product…

CVE-2023-46681 UNKNOWN 1 year, 8 months ago

Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an…

CVE-2023-45741 UNKNOWN 1 year, 8 months ago

VR-S1000 firmware Ver. 2.37 and earlier allows an attacker with access to the product's web management page to execute arbitrary OS commands.

CVE-2022-43466 UNKNOWN 2 years, 8 months ago

OS command injection vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbit…

CVE-2022-43486 UNKNOWN 2 years, 8 months ago

Hidden functionality vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to enable the debug…

CVE-2022-43443 UNKNOWN 2 years, 8 months ago

OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a specially c…