Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.35%—Buffalo Wcr-300 FirmwareBuffalo Whr-hp-g300n FirmwareBuffalo Whr-hp-gn FirmwareBuffalo Wpl-05g300 Firmware+717/12/202217/6/2026
Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the device. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and earlier, WHR-HP-GN firmware Ver. 1.87 and…
ModificadaMedia (6.8)0.33%—Buffalo Wcr-300 FirmwareBuffalo Whr-hp-g300n FirmwareBuffalo Whr-hp-gn FirmwareBuffalo Wpl-05g300 Firmware+507/12/202217/6/2026
Hidden functionality vulnerability in multiple Buffalo network devices allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and earlier, WHR-HP-GN…
ModificadaAlta (8.8)0.86%—Buffalo Bhr-4grv FirmwareBuffalo Dwr-hp-g300nh FirmwareBuffalo Hw-450hp-zwe FirmwareBuffalo Whr-300hp Firmware+2028/4/202117/6/2026
Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP firmware Ver.1.99 and prior, WHR-300 firmware Ver.1.99 and prior, WHR-G301N firmware Ver.1.86 and prior, WHR-HP-G300N…
ModificadaMedia (4.3)0.51%—Buffalo Bhr-4grv FirmwareBuffalo Dwr-hp-g300nh FirmwareBuffalo Hw-450hp-zwe FirmwareBuffalo Whr-300hp Firmware+2028/4/202117/6/2026
Disclosure of sensitive information to an unauthorized user vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP firmware Ver.1.99 and prior, WHR-300 firmware Ver.1.99 and prior, WHR-G301N…
ModificadaCrítica (9.8)3.2%—Buffalo Bhr-4rv FirmwareBuffalo Fs-g54 FirmwareBuffalo Wbr2-b11 FirmwareBuffalo Wbr2-g54 Firmware+3128/4/202117/6/2026
Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 firmware Ver.2.32 and prior, WBR2-G54-KD firmware Ver.2.32 and prior, WBR-B11 firmware Ver.2.23 and prior, WBR-G54 firmware Ver.2.23 and…
ModificadaMedia (6.1)0.78%—Buffalo Airstation Whr-g54s Firmware18/9/202017/6/2026
Cross-site scripting vulnerability in WHR-G54S firmware 1.43 and earlier allows remote attackers to inject arbitrary script via a specially crafted page.
ModificadaMedia (4.3)1.1%—Buffalo Airstation Whr-g54s Firmware18/9/202017/6/2026
Directory traversal vulnerability in WHR-G54S firmware 1.43 and earlier allows an attacker to access sensitive information such as setting values via unspecified vectors.
ModificadaMedia (5.8)0.47%—Buffalotech Bbr-4hg FirmwareBuffalotech Bbr-4mg FirmwareBuffalotech Bhr-4rv FirmwareBuffalotech Fs-g54 Firmware+399/5/201116/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify…
ModificadaMedia (4.3)0.66%—Buffalotech Airstation Whr-g54s11/9/200716/6/2026
Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attackers to make configuration changes as an administrator via HTTP requests to certain HTML pages in the res parameter with an inp req parameter to cgi-bin/cgi, as demonstrated by…