« Back to list

CVE-2017-10896

Status: ModifiedMedium (6.1)—

Cross-site scripting vulnerability in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2017-10896",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "BUFFALO INC.",
          "product": "BBR-4HG",
          "versions": [
            {
              "status": "affected",
              "version": "firmware 1.00 to 1.48"
            },
            {
              "status": "affected",
              "version": "firmware 2.00 to 2.07"
            }
          ]
        },
        {
          "vendor": "BUFFALO INC.",
          "product": "BBR-4MG",
          "versions": [
            {
              "status": "affected",
              "version": "firmware 1.00 to 1.48"
            },
            {
              "status": "affected",
              "version": "firmware 2.00 to 2.07"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-12-08T15:29:00.197",
  "references": [
    {
      "url": "http://buffalo.jp/support_s/s20171201.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN65994435/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "http://buffalo.jp/support_s/s20171201.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN65994435/index.html",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cross-site scripting vulnerability in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to inject arbitrary web script or HTML via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de tipo Cross-Site Scripting (XSS) en los routers de banda ancha Buffalo BBR-4HG y BBR-4MG con firmware 1.00 a 1.48 y 2.00 a 2.07 permite que un atacante inyecte scripts web o HTML arbitrarios utilizando vectores no especificados."
    }
  ],
  "lastModified": "2026-06-17T01:00:52.817",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:buffalo:bbr-4mg_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30C41CE6-534D-405E-8BFE-F255095BF176",
              "versionEndIncluding": "1.48",
              "versionStartIncluding": "1.00"
            },
            {
              "criteria": "cpe:2.3:o:buffalo:bbr-4mg_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F13A88E-6955-4D65-B637-40A6FDFDDC58",
              "versionEndIncluding": "2.07",
              "versionStartIncluding": "2.00"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:buffalo:bbr-4mg:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "76EA9B7A-13F2-42F3-8707-3AEC4854DD18"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:buffalo:bbr-4hg_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "86BF1D9A-2BD0-45CA-BF09-4B823367FD79",
              "versionEndIncluding": "1.48",
              "versionStartIncluding": "1.00"
            },
            {
              "criteria": "cpe:2.3:o:buffalo:bbr-4hg_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7D4B17ED-6B51-4247-B475-A5DF328821F2",
              "versionEndIncluding": "2.07",
              "versionStartIncluding": "2.00"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:buffalo:bbr-4hg:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "E38DF446-A597-4D5F-AAC8-B6B96793C446"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}