Show filters
66 Total Results
Displaying 1-10 of 66
Sort by:
Attacker Value
Unknown

CVE-2024-44072

Disclosure Date: September 10, 2024 (last updated September 10, 2024)
OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected product from the product's specific management page, an arbitrary OS command may be executed.
0
Attacker Value
Unknown

CVE-2024-26023

Disclosure Date: April 15, 2024 (last updated April 15, 2024)
OS command injection vulnerability in BUFFALO wireless LAN routers allows a logged-in user to execute arbitrary OS commands.
0
Attacker Value
Unknown

CVE-2024-23486

Disclosure Date: April 15, 2024 (last updated April 15, 2024)
Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access to the product's login page may obtain configured credentials.
0
Attacker Value
Unknown

CVE-2023-49038

Disclosure Date: January 29, 2024 (last updated February 07, 2024)
Command injection in the ping utility on Buffalo LS210D 1.78-0.03 allows a remote authenticated attacker to inject arbitrary commands onto the NAS as root.
Attacker Value
Unknown

CVE-2023-51073

Disclosure Date: January 11, 2024 (last updated January 19, 2024)
An issue in Buffalo LS210D v.1.78-0.03 allows a remote attacker to execute arbitrary code via the Firmware Update Script at /etc/init.d/update_notifications.sh.
Attacker Value
Unknown

CVE-2023-51363

Disclosure Date: December 26, 2023 (last updated January 04, 2024)
VR-S1000 firmware Ver. 2.37 and earlier allows a network-adjacent unauthenticated attacker who can access the product's web management page to obtain sensitive information.
Attacker Value
Unknown

CVE-2023-46711

Disclosure Date: December 26, 2023 (last updated January 04, 2024)
VR-S1000 firmware Ver. 2.37 and earlier uses a hard-coded cryptographic key which may allow an attacker to analyze the password of a specific product user.
Attacker Value
Unknown

CVE-2023-46681

Disclosure Date: December 26, 2023 (last updated January 04, 2024)
Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an authenticated attacker who can access to the product's command line interface to execute an arbitrary command.
Attacker Value
Unknown

CVE-2023-45741

Disclosure Date: December 26, 2023 (last updated January 04, 2024)
VR-S1000 firmware Ver. 2.37 and earlier allows an attacker with access to the product's web management page to execute arbitrary OS commands.
Attacker Value
Unknown

CVE-2023-39620

Disclosure Date: September 08, 2023 (last updated October 08, 2023)
An Issue in Buffalo America, Inc. TeraStation NAS TS5410R v.5.00 thru v.0.07 allows a remote attacker to obtain sensitive information via the guest account function.