Impact
A vulnerability exists in the Buffalo Link Station firmware 1.85‑0.01 that permits unauthenticated or guest‑level users to retrieve a list of valid usernames and their associated privilege roles by altering a parameter in requests to the /nasapi endpoint. This allows an attacker to learn account identifiers and role assignments—a disclosure that could support social engineering, credential guessing, or planning of targeted attacks. The weakness falls under CWE‑639 (Privilege‑Based Access Control Failure).
Affected Systems
Only the Buffalo Link Station device running firmware version 1.85‑0.01 is listed as affected. No other vendors or product versions are mentioned. The impact is limited to this specific firmware release.
Risk and Exploitability
The vulnerability can be triggered without authentication; any network participant who can reach the device can provoke the enumeration. The CVSS score of 6.5 indicates moderate risk. The exploitation does not require special privileges and the EPSS score is unavailable, so a precise exploitation likelihood cannot be stated. While the vulnerability is not listed in the CISA KEV catalog, the disclosure of user identities and roles could be valuable for attackers, particularly if the device hosts sensitive data or services.
OpenCVE Enrichment