CSRF Vulnerability in Buffalo WMR-433 and WMR-433W Firmware
CVE-2017-2273

8.8HIGH

Key Information:

Vendor
CVE Published:
22 July 2017

What is CVE-2017-2273?

A cross-site request forgery (CSRF) vulnerability exists in Buffalo's WMR-433 and WMR-433W firmware, which could allow a remote attacker to exploit the system by hijacking the authentication processes of the device's administrators. This can lead to unauthorized actions being performed on the device without the administrator’s consent. The affected versions are WMR-433 firmware version 1.02 and earlier, and WMR-433W firmware version 1.40 and earlier. It is critical for users to update their firmware to mitigate potential risks.

Affected Version(s)

WMR-433 firmware Ver.1.02 and earlier

WMR-433W firmware Ver.1.40 and earlier

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.