Vulnerability Description
Cross-site scripting vulnerability in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Buffalo | Bbr-4Mg Firmware | >= 1.00, <= 1.48 |
| Buffalo | Bbr-4Mg | - |
| Buffalo | Bbr-4Hg Firmware | >= 1.00, <= 1.48 |
| Buffalo | Bbr-4Hg | - |
Related Weaknesses (CWE)
References
- http://buffalo.jp/support_s/s20171201.htmlPatchVendor Advisory
- https://jvn.jp/en/jp/JVN65994435/index.htmlThird Party AdvisoryVDB Entry
- http://buffalo.jp/support_s/s20171201.htmlPatchVendor Advisory
- https://jvn.jp/en/jp/JVN65994435/index.htmlThird Party AdvisoryVDB Entry
FAQ
What is CVE-2017-10896?
CVE-2017-10896 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-site scripting vulnerability in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to inject arbitrary web script or HTML via unspec...
How severe is CVE-2017-10896?
CVE-2017-10896 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-10896?
Check the references section above for vendor advisories and patch information. Affected products include: Buffalo Bbr-4Mg Firmware, Buffalo Bbr-4Mg, Buffalo Bbr-4Hg Firmware, Buffalo Bbr-4Hg.