CVE-2011-1324
Summary
| CVE | CVE-2011-1324 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2011-05-09 19:55:00 UTC |
| Updated | 2011-05-27 04:00:00 UTC |
| Description | Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify settings, as demonstrated by changing the login password. |
Risk And Classification
Problem Types: CWE-352
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Buffalotech | As-100 | All | All | All | All |
| Hardware | Buffalotech | As-100 | All | All | All | All |
| Hardware | Buffalotech | Bbr-4hg | All | All | All | All |
| Hardware | Buffalotech | Bbr-4hg | All | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.02 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.04 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.04 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.10 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.10 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.11 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.12 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.20 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.20 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.30 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.30 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.31 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.32 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.32 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.33 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.02 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.04 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.04 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.10 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.10 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.11 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.12 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.20 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.20 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.30 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.30 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.31 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.32 | All | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.32 | beta | All | All |
| Application | Buffalotech | Bbr-4hg Firmware | 1.33 | beta | All | All |
| Hardware | Buffalotech | Bbr-4mg | All | All | All | All |
| Hardware | Buffalotech | Bbr-4mg | All | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.00 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.01 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.03 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.04 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.04 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.10 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.10 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.11 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.12 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.20 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.20 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.30 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.30 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.31 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.32 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.32 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.33 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.33 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.00 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.01 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.03 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.04 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.04 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.10 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.10 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.11 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.12 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.20 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.20 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.30 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.30 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.31 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.32 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.32 | beta | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.33 | All | All | All |
| Application | Buffalotech | Bbr-4mg Firmware | 1.33 | beta | All | All |
| Hardware | Buffalotech | Bhr-4rv | All | All | All | All |
| Hardware | Buffalotech | Bhr-4rv | All | All | All | All |
| Application | Buffalotech | Bhr-4rv Firmware | 2.31 | All | All | All |
| Application | Buffalotech | Bhr-4rv Firmware | 2.32 | prebeta | All | All |
| Application | Buffalotech | Bhr-4rv Firmware | 2.33 | prebeta | All | All |
| Application | Buffalotech | Bhr-4rv Firmware | 2.42 | All | All | All |
| Application | Buffalotech | Bhr-4rv Firmware | 2.46 | All | All | All |
| Application | Buffalotech | Bhr-4rv Firmware | 2.48 | All | All | All |
| Application | Buffalotech | Bhr-4rv Firmware | 2.31 | All | All | All |
| Application | Buffalotech | Bhr-4rv Firmware | 2.32 | prebeta | All | All |
| Application | Buffalotech | Bhr-4rv Firmware | 2.33 | prebeta | All | All |
| Application | Buffalotech | Bhr-4rv Firmware | 2.42 | All | All | All |
| Application | Buffalotech | Bhr-4rv Firmware | 2.46 | All | All | All |
| Application | Buffalotech | Bhr-4rv Firmware | 2.48 | All | All | All |
| Hardware | Buffalotech | Fs-g54 | All | All | All | All |
| Hardware | Buffalotech | Fs-g54 | All | All | All | All |
| Application | Buffalotech | Fs-g54 Firmware | 2.07 | All | All | All |
| Application | Buffalotech | Fs-g54 Firmware | 2.07 | All | All | All |
| Hardware | Buffalotech | Wer-a54g54 | All | All | All | All |
| Hardware | Buffalotech | Wer-a54g54 | All | All | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.00 | All | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.01 | beta | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.02 | All | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.03 | All | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.10 | All | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.12 | All | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.12 | beta | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.13 | All | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.00 | All | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.01 | beta | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.02 | All | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.03 | All | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.10 | All | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.12 | All | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.12 | beta | All | All |
| Application | Buffalotech | Wer-a54g54 Firmware | 1.13 | All | All | All |
| Hardware | Buffalotech | Wer-ag54 | All | All | All | All |
| Hardware | Buffalotech | Wer-ag54 | All | All | All | All |
| Application | Buffalotech | Wer-ag54 Firmware | 1.04 | All | All | All |
| Application | Buffalotech | Wer-ag54 Firmware | 1.12 | All | All | All |
| Application | Buffalotech | Wer-ag54 Firmware | 1.12 | beta | All | All |
| Application | Buffalotech | Wer-ag54 Firmware | 1.04 | All | All | All |
| Application | Buffalotech | Wer-ag54 Firmware | 1.12 | All | All | All |
| Application | Buffalotech | Wer-ag54 Firmware | 1.12 | beta | All | All |
| Hardware | Buffalotech | Wer-am54g54 | All | All | All | All |
| Hardware | Buffalotech | Wer-am54g54 | All | All | All | All |
| Application | Buffalotech | Wer-am54g54 Firmware | 1.11 | All | All | All |
| Application | Buffalotech | Wer-am54g54 Firmware | 1.12 | All | All | All |
| Application | Buffalotech | Wer-am54g54 Firmware | 1.12 | beta | All | All |
| Application | Buffalotech | Wer-am54g54 Firmware | 1.13 | All | All | All |
| Application | Buffalotech | Wer-am54g54 Firmware | 1.14 | All | All | All |
| Application | Buffalotech | Wer-am54g54 Firmware | 1.11 | All | All | All |
| Application | Buffalotech | Wer-am54g54 Firmware | 1.12 | All | All | All |
| Application | Buffalotech | Wer-am54g54 Firmware | 1.12 | beta | All | All |
| Application | Buffalotech | Wer-am54g54 Firmware | 1.13 | All | All | All |
| Application | Buffalotech | Wer-am54g54 Firmware | 1.14 | All | All | All |
| Hardware | Buffalotech | Wer-amg54 | All | All | All | All |
| Hardware | Buffalotech | Wer-amg54 | All | All | All | All |
| Application | Buffalotech | Wer-amg54 Firmware | 1.11 | All | All | All |
| Application | Buffalotech | Wer-amg54 Firmware | 1.12 | All | All | All |
| Application | Buffalotech | Wer-amg54 Firmware | 1.14 | All | All | All |
| Application | Buffalotech | Wer-amg54 Firmware | 1.11 | All | All | All |
| Application | Buffalotech | Wer-amg54 Firmware | 1.12 | All | All | All |
| Application | Buffalotech | Wer-amg54 Firmware | 1.14 | All | All | All |
| Hardware | Buffalotech | Whr-am54g54 | All | All | All | All |
| Hardware | Buffalotech | Whr-am54g54 | All | All | All | All |
| Application | Buffalotech | Whr-am54g54 Firmware | 1.30 | All | All | All |
| Application | Buffalotech | Whr-am54g54 Firmware | 1.38 | All | All | All |
| Application | Buffalotech | Whr-am54g54 Firmware | 1.40 | All | All | All |
| Application | Buffalotech | Whr-am54g54 Firmware | 1.42 | All | All | All |
| Application | Buffalotech | Whr-am54g54 Firmware | 1.30 | All | All | All |
| Application | Buffalotech | Whr-am54g54 Firmware | 1.38 | All | All | All |
| Application | Buffalotech | Whr-am54g54 Firmware | 1.40 | All | All | All |
| Application | Buffalotech | Whr-am54g54 Firmware | 1.42 | All | All | All |
| Hardware | Buffalotech | Whr-amg54 | All | All | All | All |
| Hardware | Buffalotech | Whr-amg54 | All | All | All | All |
| Application | Buffalotech | Whr-amg54 Firmware | 1.31 | All | All | All |
| Application | Buffalotech | Whr-amg54 Firmware | 1.38 | All | All | All |
| Application | Buffalotech | Whr-amg54 Firmware | 1.40 | All | All | All |
| Application | Buffalotech | Whr-amg54 Firmware | 1.42 | All | All | All |
| Application | Buffalotech | Whr-amg54 Firmware | 1.31 | All | All | All |
| Application | Buffalotech | Whr-amg54 Firmware | 1.38 | All | All | All |
| Application | Buffalotech | Whr-amg54 Firmware | 1.40 | All | All | All |
| Application | Buffalotech | Whr-amg54 Firmware | 1.42 | All | All | All |
| Hardware | Buffalotech | Whr-ampg | All | All | All | All |
| Hardware | Buffalotech | Whr-ampg | All | All | All | All |
| Application | Buffalotech | Whr-ampg Firmware | 1.46 | All | All | All |
| Application | Buffalotech | Whr-ampg Firmware | 1.46 | All | All | All |
| Hardware | Buffalotech | Whr-g | All | All | All | All |
| Hardware | Buffalotech | Whr-g | All | All | All | All |
| Hardware | Buffalotech | Whr-g54s | All | All | All | All |
| Hardware | Buffalotech | Whr-g54s | All | All | All | All |
| Application | Buffalotech | Whr-g54s Firmware | 1.20 | All | All | All |
| Application | Buffalotech | Whr-g54s Firmware | 1.21 | All | All | All |
| Application | Buffalotech | Whr-g54s Firmware | 1.23 | All | All | All |
| Application | Buffalotech | Whr-g54s Firmware | 1.38 | All | All | All |
| Application | Buffalotech | Whr-g54s Firmware | 1.40 | All | All | All |
| Application | Buffalotech | Whr-g54s Firmware | 1.42 | All | All | All |
| Application | Buffalotech | Whr-g54s Firmware | 1.20 | All | All | All |
| Application | Buffalotech | Whr-g54s Firmware | 1.21 | All | All | All |
| Application | Buffalotech | Whr-g54s Firmware | 1.23 | All | All | All |
| Application | Buffalotech | Whr-g54s Firmware | 1.38 | All | All | All |
| Application | Buffalotech | Whr-g54s Firmware | 1.40 | All | All | All |
| Application | Buffalotech | Whr-g54s Firmware | 1.42 | All | All | All |
| Application | Buffalotech | Whr-g Firmware | 1.46 | All | All | All |
| Application | Buffalotech | Whr-g Firmware | 1.46 | All | All | All |
| Hardware | Buffalotech | Whr-hp-ampg | All | All | All | All |
| Hardware | Buffalotech | Whr-hp-ampg | All | All | All | All |
| Application | Buffalotech | Whr-hp-ampg Firmware | 1.32 | All | All | All |
| Application | Buffalotech | Whr-hp-ampg Firmware | 1.32 | All | All | All |
| Hardware | Buffalotech | Whr-hp-g | All | All | All | All |
| Hardware | Buffalotech | Whr-hp-g | All | All | All | All |
| Hardware | Buffalotech | Whr-hp-g54 | All | All | All | All |
| Hardware | Buffalotech | Whr-hp-g54 | All | All | All | All |
| Application | Buffalotech | Whr-hp-g54 Firmware | 1.20 | All | All | All |
| Application | Buffalotech | Whr-hp-g54 Firmware | 1.21 | All | All | All |
| Application | Buffalotech | Whr-hp-g54 Firmware | 1.23 | All | All | All |
| Application | Buffalotech | Whr-hp-g54 Firmware | 1.38 | All | All | All |
| Application | Buffalotech | Whr-hp-g54 Firmware | 1.40 | All | All | All |
| Application | Buffalotech | Whr-hp-g54 Firmware | 1.42 | All | All | All |
| Application | Buffalotech | Whr-hp-g54 Firmware | 1.20 | All | All | All |
| Application | Buffalotech | Whr-hp-g54 Firmware | 1.21 | All | All | All |
| Application | Buffalotech | Whr-hp-g54 Firmware | 1.23 | All | All | All |
| Application | Buffalotech | Whr-hp-g54 Firmware | 1.38 | All | All | All |
| Application | Buffalotech | Whr-hp-g54 Firmware | 1.40 | All | All | All |
| Application | Buffalotech | Whr-hp-g54 Firmware | 1.42 | All | All | All |
| Application | Buffalotech | Whr-hp-g Firmware | 1.46 | All | All | All |
| Application | Buffalotech | Whr-hp-g Firmware | 1.46 | All | All | All |
| Hardware | Buffalotech | Wzr-ampg144nh | All | All | All | All |
| Hardware | Buffalotech | Wzr-ampg144nh | All | All | All | All |
| Application | Buffalotech | Wzr-ampg144nh Firmware | 1.47 | All | All | All |
| Application | Buffalotech | Wzr-ampg144nh Firmware | 1.48 | beta | All | All |
| Application | Buffalotech | Wzr-ampg144nh Firmware | 1.47 | All | All | All |
| Application | Buffalotech | Wzr-ampg144nh Firmware | 1.48 | beta | All | All |
| Hardware | Buffalotech | Wzr-ampg300nh | All | All | All | All |
| Hardware | Buffalotech | Wzr-ampg300nh | All | All | All | All |
| Application | Buffalotech | Wzr-ampg300nh Firmware | 1.48 | All | All | All |
| Application | Buffalotech | Wzr-ampg300nh Firmware | 1.48 | All | All | All |
| Hardware | Buffalotech | Wzr-g144n | All | All | All | All |
| Hardware | Buffalotech | Wzr-g144n | All | All | All | All |
| Hardware | Buffalotech | Wzr-g144nh | All | All | All | All |
| Hardware | Buffalotech | Wzr-g144nh | All | All | All | All |
| Application | Buffalotech | Wzr-g144nh Firmware | 1.45 | All | All | All |
| Application | Buffalotech | Wzr-g144nh Firmware | 1.47 | All | All | All |
| Application | Buffalotech | Wzr-g144nh Firmware | 1.47 | beta | All | All |
| Application | Buffalotech | Wzr-g144nh Firmware | 1.48 | All | All | All |
| Application | Buffalotech | Wzr-g144nh Firmware | 1.45 | All | All | All |
| Application | Buffalotech | Wzr-g144nh Firmware | 1.47 | All | All | All |
| Application | Buffalotech | Wzr-g144nh Firmware | 1.47 | beta | All | All |
| Application | Buffalotech | Wzr-g144nh Firmware | 1.48 | All | All | All |
| Application | Buffalotech | Wzr-g144n Firmware | 1.45 | All | All | All |
| Application | Buffalotech | Wzr-g144n Firmware | 1.46 | beta | All | All |
| Application | Buffalotech | Wzr-g144n Firmware | 1.47 | All | All | All |
| Application | Buffalotech | Wzr-g144n Firmware | 1.47 | beta | All | All |
| Application | Buffalotech | Wzr-g144n Firmware | 1.45 | All | All | All |
| Application | Buffalotech | Wzr-g144n Firmware | 1.46 | beta | All | All |
| Application | Buffalotech | Wzr-g144n Firmware | 1.47 | All | All | All |
| Application | Buffalotech | Wzr-g144n Firmware | 1.47 | beta | All | All |
| Hardware | Buffalotech | Wzr2-g300n | All | All | All | All |
| Hardware | Buffalotech | Wzr2-g300n | All | All | All | All |
| Application | Buffalotech | Wzr2-g300n Firmware | 1.48 | All | All | All |
| Application | Buffalotech | Wzr2-g300n Firmware | 1.50 | beta | All | All |
| Application | Buffalotech | Wzr2-g300n Firmware | 1.48 | All | All | All |
| Application | Buffalotech | Wzr2-g300n Firmware | 1.50 | beta | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#50505257: Multiple Buffalo routers vulnerable to cross-site request forgery | JVN | jvn.jp | |
| buffalo.jp/support_s/20080808/csrf.html | CONFIRM | buffalo.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.