Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify settings, as demonstrated by changing the login password.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Buffalotech
Subscribe
|
As-100
Subscribe
Bbr-4hg
Subscribe
Bbr-4hg Firmware
Subscribe
Bbr-4mg
Subscribe
Bbr-4mg Firmware
Subscribe
Bhr-4rv
Subscribe
Bhr-4rv Firmware
Subscribe
Fs-g54
Subscribe
Fs-g54 Firmware
Subscribe
Wer-a54g54
Subscribe
Wer-a54g54 Firmware
Subscribe
Wer-ag54
Subscribe
Wer-ag54 Firmware
Subscribe
Wer-am54g54
Subscribe
Wer-am54g54 Firmware
Subscribe
Wer-amg54
Subscribe
Wer-amg54 Firmware
Subscribe
Whr-am54g54
Subscribe
Whr-am54g54 Firmware
Subscribe
Whr-amg54
Subscribe
Whr-amg54 Firmware
Subscribe
Whr-ampg
Subscribe
Whr-ampg Firmware
Subscribe
Whr-g
Subscribe
Whr-g54s
Subscribe
Whr-g54s Firmware
Subscribe
Whr-g Firmware
Subscribe
Whr-hp-ampg
Subscribe
Whr-hp-ampg Firmware
Subscribe
Whr-hp-g
Subscribe
Whr-hp-g54
Subscribe
Whr-hp-g54 Firmware
Subscribe
Whr-hp-g Firmware
Subscribe
Wzr-ampg144nh
Subscribe
Wzr-ampg144nh Firmware
Subscribe
Wzr-ampg300nh
Subscribe
Wzr-ampg300nh Firmware
Subscribe
Wzr-g144n
Subscribe
Wzr-g144n Firmware
Subscribe
Wzr-g144nh
Subscribe
Wzr-g144nh Firmware
Subscribe
Wzr2-g300n
Subscribe
Wzr2-g300n Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2011-1332 | Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify settings, as demonstrated by changing the login password. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-09-17T03:22:31.307Z
Reserved: 2011-03-09T00:00:00Z
Link: CVE-2011-1324
No data.
Status : Deferred
Published: 2011-05-09T19:55:03.507
Modified: 2025-04-11T00:51:21.963
Link: CVE-2011-1324
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD