MEDIUM · 4.3

CVE-2021-3511

Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE fi...

Vulnerability Description

Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP firmware Ver.1.99 and prior, WHR-300 firmware Ver.1.99 and prior, WHR-G301N firmware Ver.1.86 and prior, WHR-HP-G300N firmware Ver.1.99 and prior, WHR-HP-GN firmware Ver.1.86 and prior, WPL-05G300 firmware Ver.1.87 and prior, WZR-450HP-CWT firmware Ver.1.99 and prior, WZR-450HP-UB firmware Ver.1.99 and prior, WZR-HP-AG300H firmware Ver.1.75 and prior, WZR-HP-G300NH firmware Ver.1.83 and prior, WZR-HP-G301NH firmware Ver.1.83 and prior, WZR-HP-G302H firmware Ver.1.85 and prior, WZR-HP-G450H firmware Ver.1.89 and prior, WZR-300HP firmware Ver.1.99 and prior, WZR-450HP firmware Ver.1.99 and prior, WZR-600DHP firmware Ver.1.99 and prior, WZR-D1100H firmware Ver.1.99 and prior, FS-HP-G300N firmware Ver.3.32 and prior, FS-600DHP firmware Ver.3.38 and prior, FS-R600DHP firmware Ver.3.39 and prior, and FS-G300N firmware Ver.3.13 and prior) allows remote unauthenticated attackers to obtain information such as configuration via unspecified vectors.

CVSS Score

4.3

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
BuffaloBhr-4Grv Firmware< 2.00
BuffaloBhr-4Grv-
BuffaloDwr-Hp-G300Nh Firmware< 1.84
BuffaloDwr-Hp-G300Nh-
BuffaloHw-450Hp-Zwe Firmware< 2.00
BuffaloHw-450Hp-Zwe-
BuffaloWhr-300Hp Firmware< 2.00
BuffaloWhr-300Hp-
BuffaloWhr-300 Firmware< 2.00
BuffaloWhr-300-
BuffaloWhr-G301N Firmware< 1.87
BuffaloWhr-G301N-
BuffaloWhr-Hp-G300N Firmware< 2.00
BuffaloWhr-Hp-G300N-
BuffaloWhr-Hp-Gn Firmware< 1.87
BuffaloWhr-Hp-Gn-
BuffaloWpl-05G300 Firmware< 1.88
BuffaloWpl-05G300-
BuffaloWzr-450Hp-Cwt Firmware< 2.00
BuffaloWzr-450Hp-Cwt-

References

FAQ

What is CVE-2021-3511?

CVE-2021-3511 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE fi...

How severe is CVE-2021-3511?

CVE-2021-3511 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-3511?

Check the references section above for vendor advisories and patch information. Affected products include: Buffalo Bhr-4Grv Firmware, Buffalo Bhr-4Grv, Buffalo Dwr-Hp-G300Nh Firmware, Buffalo Dwr-Hp-G300Nh, Buffalo Hw-450Hp-Zwe Firmware.