Hard-Coded Credentials Vulnerability in Buffalo Network Devices
CVE-2023-26588

7.5HIGH

Key Information:

Vendor
CVE Published:
11 April 2023

What is CVE-2023-26588?

A vulnerability exists in Buffalo network devices due to the presence of hard-coded credentials, allowing unauthorized users to gain access to the product's debug functions. This flaw impacts various models and firmware versions, potentially compromising network security and operational integrity. Users are advised to update their firmware to the latest versions to mitigate this vulnerability.

Affected Version(s)

BS-GSL and BS-GS series BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03 and earlier, BS-GSL2016 firmware Ver. 1.10-0.03 and earlier, BS-GS2008 firmware Ver. 1.0.10.01 and earlier, BS-GS2016 firmware Ver. 1.0.10.01 and earlier, BS-GS2024 firmware Ver. 1.0.10.01 and earlier, BS-GS2048 firmware Ver. 1.0.10.01 and earlier, BS-GS2008P firmware Ver. 1.0.10.01 and earlier, BS-GS2016P firmware Ver. 1.0.10.01 and earlier, and BS-GS2024P firmware Ver. 1.0.10.01 and earlier

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.