MEDIUM · 5.8

CVE-2011-1324

Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2...

Vulnerability Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify settings, as demonstrated by changing the login password.

CVSS Score

5.8

MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
BuffalotechBbr-4Hg Firmware1.02
BuffalotechBbr-4Mg Firmware1.00
BuffalotechBhr-4Rv Firmware2.31
BuffalotechFs-G54 Firmware2.07
BuffalotechWer-A54G54 Firmware1.00
BuffalotechWer-Ag54 Firmware1.04
BuffalotechWer-Am54G54 Firmware1.11
BuffalotechWer-Amg54 Firmware1.11
BuffalotechWhr-Am54G54 Firmware1.30
BuffalotechWhr-Amg54 Firmware1.31
BuffalotechWhr-Ampg Firmware1.46
BuffalotechWhr-G Firmware1.46
BuffalotechWhr-G54S Firmware1.20
BuffalotechWhr-Hp-Ampg Firmware1.32
BuffalotechWhr-Hp-G Firmware1.46
BuffalotechWhr-Hp-G54 Firmware1.20
BuffalotechWzr-Ampg144Nh Firmware1.47
BuffalotechWzr-Ampg300Nh Firmware1.48
BuffalotechWzr-G144N Firmware1.45
BuffalotechWzr-G144Nh Firmware1.45

Related Weaknesses (CWE)

References

FAQ

What is CVE-2011-1324?

CVE-2011-1324 is a vulnerability with a CVSS score of 5.8 (MEDIUM). Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2...

How severe is CVE-2011-1324?

CVE-2011-1324 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2011-1324?

Check the references section above for vendor advisories and patch information. Affected products include: Buffalotech Bbr-4Hg Firmware, Buffalotech Bbr-4Mg Firmware, Buffalotech Bhr-4Rv Firmware, Buffalotech Fs-G54 Firmware, Buffalotech Wer-A54G54 Firmware.