CVE-2022-40966

Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the device. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and earlier, WHR-HP-GN firmware Ver. 1.87 and earlier, WPL-05G300 firmware Ver. 1.88 and earlier, WRM-D2133HP firmware Ver. 2.85 and earlier, WRM-D2133HS firmware Ver. 2.96 and earlier, WTR-M2133HP firmware Ver. 2.85 and earlier, WTR-M2133HS firmware Ver. 2.96 and earlier, WXR-1900DHP firmware Ver. 2.50 and earlier, WXR-1900DHP2 firmware Ver. 2.59 and earlier, WXR-1900DHP3 firmware Ver. 2.63 and earlier, WXR-5950AX12 firmware Ver. 3.40 and earlier, WXR-6000AX12B firmware Ver. 3.40 and earlier, WXR-6000AX12S firmware Ver. 3.40 and earlier, WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, WZR-1750DHP2 firmware Ver. 2.31 and earlier, WZR-HP-AG300H firmware Ver. 1.76 and earlier, WZR-HP-G302H firmware Ver. 1.86 and earlier, WEM-1266 firmware Ver. 2.85 and earlier, WEM-1266WP firmware Ver. 2.85 and earlier, WLAE-AG300N firmware Ver. 1.86 and earlier, FS-600DHP firmware Ver. 3.40 and earlier, FS-G300N firmware Ver. 3.14 and earlier, FS-HP-G300N firmware Ver. 3.33 and earlier, FS-R600DHP firmware Ver. 3.40 and earlier, BHR-4GRV firmware Ver. 2.00 and earlier, DWR-HP-G300NH firmware Ver. 1.84 and earlier, DWR-PG firmware Ver. 1.83 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WER-A54G54 firmware Ver. 1.43 and earlier, WER-AG54 firmware Ver. 1.43 and earlier, WER-AM54G54 firmware Ver. 1.43 and earlier, WER-AMG54 firmware Ver. 1.43 and earlier, WHR-300 firmware Ver. 2.00 and earlier, WHR-300HP firmware Ver. 2.00 and earlier, WHR-AM54G54 firmware Ver. 1.43 and earlier, WHR-AMG54 firmware Ver. 1.43 and earlier, WHR-AMPG firmware Ver. 1.52 and earlier, WHR-G firmware Ver. 1.49 and earlier, WHR-G300N firmware Ver. 1.65 and earlier, WHR-G301N firmware Ver. 1.87 and earlier, WHR-G54S firmware Ver. 1.43 and earlier, WHR-G54S-NI firmware Ver. 1.24 and earlier, WHR-HP-AMPG firmware Ver. 1.43 and earlier, WHR-HP-G firmware Ver. 1.49 and earlier, WHR-HP-G54 firmware Ver. 1.43 and earlier, WLI-H4-D600 firmware Ver. 1.88 and earlier, WS024BF firmware Ver. 1.60 and earlier, WS024BF-NW firmware Ver. 1.60 and earlier, WXR-1750DHP firmware Ver. 2.60 and earlier, WXR-1750DHP2 firmware Ver. 2.60 and earlier, WZR-1166DHP firmware Ver. 2.18 and earlier, WZR-1166DHP2 firmware Ver. 2.18 and earlier, WZR-1750DHP firmware Ver. 2.30 and earlier, WZR2-G300N firmware Ver. 1.55 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, WZR-600DHP3 firmware Ver. 2.19 and earlier, WZR-900DHP2 firmware Ver. 2.19 and earlier, WZR-AGL300NH firmware Ver. 1.55 and earlier, WZR-AMPG144NH firmware Ver. 1.49 and earlier, WZR-AMPG300NH firmware Ver. 1.51 and earlier, WZR-D1100H firmware Ver. 2.00 and earlier, WZR-G144N firmware Ver. 1.48 and earlier, WZR-G144NH firmware Ver. 1.48 and earlier, WZR-HP-G300NH firmware Ver. 1.84 and earlier, WZR-HP-G301NH firmware Ver. 1.84 and earlier, WZR-HP-G450H firmware Ver. 1.90 and earlier, WZR-S1750DHP firmware Ver. 2.32 and earlier, WZR-S600DHP firmware Ver. 2.19 and earlier, and WZR-S900DHP firmware Ver. 2.19 and earlier.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
jpcertCNA
---
---
CVEADP
---
---
CISA-ADPADP
8.8 HIGH
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
buffalowcr-300_firmware
𝑥
≤ 1.87
buffalowhr-hp-g300n_firmware
𝑥
≤ 2.00
buffalowhr-hp-gn_firmware
𝑥
≤ 1.87
buffalowpl-05g300_firmware
𝑥
≤ 1.88
buffalowrm-d2133hp_firmware
𝑥
≤ 2.85
buffalowrm-d2133hs_firmware
𝑥
≤ 2.96
buffalowtr-m2133hp_firmware
𝑥
≤ 2.85
buffalowtr-m2133hs_firmware
𝑥
≤ 2.96
buffalowxr-1900dhp_firmware
𝑥
≤ 2.50
buffalowxr-1900dhp2_firmware
𝑥
≤ 2.59
buffalowxr-1900dhp3_firmware
𝑥
≤ 2.63
buffalowxr-5950ax12_firmware
𝑥
≤ 3.40
buffalowxr-6000ax12b_firmware
𝑥
≤ 3.40
buffalowxr-6000ax12s_firmware
𝑥
≤ 3.40
buffalowzr-300hp_firmware
𝑥
≤ 2.00
buffalowzr-450hp_firmware
𝑥
≤ 2.00
buffalowzr-600dhp_firmware
𝑥
≤ 2.00
buffalowzr-900dhp_firmware
𝑥
≤ 1.15
buffalowzr-1750dhp2_firmware
𝑥
≤ 2.31
buffalowzr-hp-ag300h_firmware
𝑥
≤ 1.76
buffalowzr-hp-g302h_firmware
𝑥
≤ 1.86
buffalowem-1266_firmware
𝑥
≤ 2.85
buffalowem-1266wp_firmware
𝑥
≤ 2.85
buffalowlae-ag300n_firmware
𝑥
≤ 1.86
buffalofs-600dhp_firmware
𝑥
≤ 3.40
buffalofs-g300n_firmware
𝑥
≤ 3.14
buffalofs-hp-g300n_firmware
𝑥
≤ 3.33
buffalofs-r600dhp_firmware
𝑥
≤ 3.40
buffalobhr-4grv_firmware
𝑥
≤ 2.00
buffalodwr-hp-g300nh_firmware
𝑥
≤ 1.84
buffalodwr-pg_firmware
𝑥
≤ 1.83
buffalohw-450hp-zwe_firmware
𝑥
≤ 2.00
buffalower-a54g54_firmware
𝑥
≤ 1.43
buffalower-ag54_firmware
𝑥
≤ 1.43
buffalower-am54g54_firmware
𝑥
≤ 1.43
buffalower-amg54_firmware
𝑥
≤ 1.43
buffalowhr-300_firmware
𝑥
≤ 2.00
buffalowhr-300hp_firmware
𝑥
≤ 2.00
buffalowhr-am54g54_firmware
𝑥
≤ 1.43
buffalowhr-amg54_firmware
𝑥
≤ 1.43
buffalowhr-ampg_firmware
𝑥
≤ 1.52
buffalowhr-g_firmware
𝑥
≤ 1.49
buffalowhr-g300n_firmware
𝑥
≤ 1.65
buffalowhr-g301n_firmware
𝑥
≤ 1.87
buffalowhr-g54s_firmware
𝑥
≤ 1.43
buffalowhr-g54s-ni_firmware
𝑥
≤ 1.24
buffalowhr-hp-ampg_firmware
𝑥
≤ 1.43
buffalowhr-hp-g_firmware
𝑥
≤ 1.49
buffalowhr-hp-g54_firmware
𝑥
≤ 1.43
buffalowli-h4-d600_firmware
𝑥
≤ 1.88
buffalows024bf_firmware
𝑥
≤ 1.60
buffalows024bf-nw_firmware
𝑥
≤ 1.60
buffalowxr-1750dhp_firmware
𝑥
≤ 2.60
buffalowxr-1750dhp2_firmware
𝑥
≤ 2.60
buffalowzr-1166dhp_firmware
𝑥
≤ 2.18
buffalowzr-1166dhp2_firmware
𝑥
≤ 2.18
buffalowzr-1750dhp_firmware
𝑥
≤ 2.30
buffalowzr2-g300n_firmware
𝑥
≤ 1.55
buffalowzr-450hp-cwt_firmware
𝑥
≤ 2.00
buffalowzr-450hp-ub_firmware
𝑥
≤ 2.00
buffalowzr-600dhp2_firmware
𝑥
≤ 1.15
buffalowzr-600dhp3_firmware
𝑥
≤ 2.19
buffalowzr-900dhp2_firmware
𝑥
≤ 2.19
buffalowzr-agl300nh_firmware
𝑥
≤ 1.55
buffalowzr-ampg144nh_firmware
𝑥
≤ 1.49
buffalowzr-ampg300nh_firmware
𝑥
≤ 1.51
buffalowzr-d1100h_firmware
𝑥
≤ 2.00
buffalowzr-g144n_firmware
𝑥
≤ 1.48
buffalowzr-g144nh_firmware
𝑥
≤ 1.48
buffalowzr-hp-g300nh_firmware
𝑥
≤ 1.84
buffalowzr-hp-g301nh_firmware
𝑥
≤ 1.84
buffalowzr-hp-g450h_firmware
𝑥
≤ 1.90
buffalowzr-s1750dhp_firmware
𝑥
≤ 2.32
buffalowzr-s600dhp_firmware
𝑥
≤ 2.19
buffalowzr-s900dhp_firmware
𝑥
≤ 2.19
𝑥
= Vulnerable software versions