Description
Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WHR-600D devices with firmware 1.90 and earlier, WMR-300 devices with firmware 1.90 and earlier, WMR-433 devices with firmware 1.01 and earlier, and WSR-1166DHP devices with firmware 1.01 and earlier allows remote attackers to hijack the authentication of arbitrary users.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-2238 | Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WHR-600D devices with firmware 1.90 and earlier, WMR-300 devices with firmware 1.90 and earlier, WMR-433 devices with firmware 1.01 and earlier, and WSR-1166DHP devices with firmware 1.01 and earlier allows remote attackers to hijack the authentication of arbitrary users. |
References
History
No history.
Subscriptions
Buffalotech
Subscribe
Bhr-4grv2
Subscribe
Bhr-4grv2 Firmware
Subscribe
Wex-300
Subscribe
Wex-300 Firmware
Subscribe
Whr-1166dhp
Subscribe
Whr-1166dhp Firmware
Subscribe
Whr-300hp2
Subscribe
Whr-300hp2 Firmware
Subscribe
Whr-600d
Subscribe
Whr-600d Firmware
Subscribe
Wmr-300
Subscribe
Wmr-300 Firmware
Subscribe
Wmr-433
Subscribe
Wmr-433 Firmware
Subscribe
Wsr-1166dhp
Subscribe
Wsr-1166dhp Firmware
Subscribe
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-05T22:48:13.124Z
Reserved: 2015-12-26T00:00:00.000Z
Link: CVE-2016-1134
No data.
Status : Deferred
Published: 2016-01-22T11:59:05.117
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-1134
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD