Vulnerability Description
Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP firmware Ver.1.99 and prior, WHR-300 firmware Ver.1.99 and prior, WHR-G301N firmware Ver.1.86 and prior, WHR-HP-G300N firmware Ver.1.99 and prior, WHR-HP-GN firmware Ver.1.86 and prior, WPL-05G300 firmware Ver.1.87 and prior, WZR-450HP-CWT firmware Ver.1.99 and prior, WZR-450HP-UB firmware Ver.1.99 and prior, WZR-HP-AG300H firmware Ver.1.75 and prior, WZR-HP-G300NH firmware Ver.1.83 and prior, WZR-HP-G301NH firmware Ver.1.83 and prior, WZR-HP-G302H firmware Ver.1.85 and prior, WZR-HP-G450H firmware Ver.1.89 and prior, WZR-300HP firmware Ver.1.99 and prior, WZR-450HP firmware Ver.1.99 and prior, WZR-600DHP firmware Ver.1.99 and prior, WZR-D1100H firmware Ver.1.99 and prior, FS-HP-G300N firmware Ver.3.32 and prior, FS-600DHP firmware Ver.3.38 and prior, FS-R600DHP firmware Ver.3.39 and prior, and FS-G300N firmware Ver.3.13 and prior) allows remote unauthenticated attackers to obtain information such as configuration via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Buffalo | Bhr-4Grv Firmware | < 2.00 |
| Buffalo | Bhr-4Grv | - |
| Buffalo | Dwr-Hp-G300Nh Firmware | < 1.84 |
| Buffalo | Dwr-Hp-G300Nh | - |
| Buffalo | Hw-450Hp-Zwe Firmware | < 2.00 |
| Buffalo | Hw-450Hp-Zwe | - |
| Buffalo | Whr-300Hp Firmware | < 2.00 |
| Buffalo | Whr-300Hp | - |
| Buffalo | Whr-300 Firmware | < 2.00 |
| Buffalo | Whr-300 | - |
| Buffalo | Whr-G301N Firmware | < 1.87 |
| Buffalo | Whr-G301N | - |
| Buffalo | Whr-Hp-G300N Firmware | < 2.00 |
| Buffalo | Whr-Hp-G300N | - |
| Buffalo | Whr-Hp-Gn Firmware | < 1.87 |
| Buffalo | Whr-Hp-Gn | - |
| Buffalo | Wpl-05G300 Firmware | < 1.88 |
| Buffalo | Wpl-05G300 | - |
| Buffalo | Wzr-450Hp-Cwt Firmware | < 2.00 |
| Buffalo | Wzr-450Hp-Cwt | - |
References
- https://jvn.jp/en/vu/JVNVU99235714/index.htmlThird Party Advisory
- https://www.buffalo.jp/news/detail/20210427-01.htmlVendor Advisory
- https://jvn.jp/en/vu/JVNVU99235714/index.htmlThird Party Advisory
- https://www.buffalo.jp/news/detail/20210427-01.htmlVendor Advisory
FAQ
What is CVE-2021-3511?
CVE-2021-3511 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE fi...
How severe is CVE-2021-3511?
CVE-2021-3511 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-3511?
Check the references section above for vendor advisories and patch information. Affected products include: Buffalo Bhr-4Grv Firmware, Buffalo Bhr-4Grv, Buffalo Dwr-Hp-G300Nh Firmware, Buffalo Dwr-Hp-G300Nh, Buffalo Hw-450Hp-Zwe Firmware.