Impact
The vulnerability is an authentication bypass that permits an attacker to modify critical configuration settings on Buffalo Wi‑Fi routers without providing valid credentials. The official description states that such an attacker can alter configuration without authentication, which directly threatens the integrity of the device’s network settings and potentially its overall security posture.
Affected Systems
The affected devices are Buffalo Wi‑Fi router products distributed by Buffalo Inc. No specific firmware versions are listed, so all models that have not applied a firmware update which addresses this issue are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. Because the flaw does not require any authentication, the likely attack vector is remote, as an attacker could send crafted traffic over the network to the router. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but the high severity and remote nature of the exploitability warrant immediate action to mitigate the risk of unauthorized configuration changes.
OpenCVE Enrichment