Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.35% | — | Buffalo Wcr-300 FirmwareBuffalo Whr-hp-g300n FirmwareBuffalo Whr-hp-gn FirmwareBuffalo Wpl-05g300 Firmware+71 | 7/12/2022 | 17/6/2026 | Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the device. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and earlier, WHR-HP-GN firmware Ver. 1.87 and… | |
| Modificada | Media (6.8) | 0.33% | — | Buffalo Wcr-300 FirmwareBuffalo Whr-hp-g300n FirmwareBuffalo Whr-hp-gn FirmwareBuffalo Wpl-05g300 Firmware+50 | 7/12/2022 | 17/6/2026 | Hidden functionality vulnerability in multiple Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and earlier, WHR-HP-GN… | |
| Modificada | Alta (8.8) | 0.86% | — | Buffalo Bhr-4grv FirmwareBuffalo Dwr-hp-g300nh FirmwareBuffalo Hw-450hp-zwe FirmwareBuffalo Whr-300hp Firmware+20 | 28/4/2021 | 17/6/2026 | Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP firmware Ver.1.99 and prior, WHR-300 firmware Ver.1.99 and prior, WHR-G301N firmware Ver.1.86 and prior, WHR-HP-G300N… | |
| Modificada | Media (4.3) | 0.51% | — | Buffalo Bhr-4grv FirmwareBuffalo Dwr-hp-g300nh FirmwareBuffalo Hw-450hp-zwe FirmwareBuffalo Whr-300hp Firmware+20 | 28/4/2021 | 17/6/2026 | Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP firmware Ver.1.99 and prior, WHR-300 firmware Ver.1.99 and prior, WHR-G301N… | |
| Modificada | Crítica (9.8) | 3.2% | — | Buffalo Bhr-4rv FirmwareBuffalo Fs-g54 FirmwareBuffalo Wbr2-b11 FirmwareBuffalo Wbr2-g54 Firmware+31 | 28/4/2021 | 17/6/2026 | Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 firmware Ver.2.32 and prior, WBR2-G54-KD firmware Ver.2.32 and prior, WBR-B11 firmware Ver.2.23 and prior, WBR-G54 firmware Ver.2.23 and… | |
| Modificada | Media (6.1) | 0.78% | — | Buffalo Airstation Whr-g54s Firmware | 18/9/2020 | 17/6/2026 | Cross-site scripting vulnerability in WHR-G54S firmware 1.43 and earlier allows remote attackers to inject arbitrary script via a specially crafted page. | |
| Modificada | Media (4.3) | 1.1% | — | Buffalo Airstation Whr-g54s Firmware | 18/9/2020 | 17/6/2026 | Directory traversal vulnerability in WHR-G54S firmware 1.43 and earlier allows an attacker to access sensitive information such as setting values via unspecified vectors. | |
| Modificada | Media (5.8) | 0.47% | — | Buffalotech Bbr-4hg FirmwareBuffalotech Bbr-4mg FirmwareBuffalotech Bhr-4rv FirmwareBuffalotech Fs-g54 Firmware+39 | 9/5/2011 | 16/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify… | |
| Modificada | Media (4.3) | 0.66% | — | Buffalotech Airstation Whr-g54s | 11/9/2007 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attackers to make configuration changes as an administrator via HTTP requests to certain HTML pages in the res parameter with an inp req parameter to cgi-bin/cgi, as demonstrated by… |