Known Vulnerabilities for products from Buffalotech

Listed below are 13 of the newest known vulnerabilities associated with the vendor "Buffalotech".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Buffalotech can be found at device.report : Buffalotech

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2016-7826 json Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated a... Not Provided 2017-06-09 2025-04-20
CVE-2016-7825 json Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated a... Not Provided 2017-06-09 2025-04-20
CVE-2016-7824 json Buffalo NC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to bypass access restriction ... Not Provided 2017-06-09 2025-04-20
CVE-2016-7823 json Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated ... Not Provided 2017-06-09 2025-04-20
CVE-2016-7822 json Cross-site request forgery (CSRF) vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows r... Not Provided 2017-06-09 2025-04-20
CVE-2016-7821 json Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allow remote attackers to cause a denial of service against... Not Provided 2017-06-09 2025-04-20
CVE-2016-1135 json Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with fi... Not Provided 2016-01-22 2026-05-06
CVE-2016-1134 json Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices ... Not Provided 2016-01-22 2026-05-06
CVE-2015-8262 json Buffalo WZR-600DHP2 devices with firmware 2.09, 2.13, and 2.16 use an improper algorithm for selecting the ID value in the he... Not Provided 2015-12-27 2026-05-06
CVE-2014-9284 json The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and earlier... Not Provided 2015-06-09 2026-05-06
CVE-2011-1324 json Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR s... Not Provided 2011-05-09 2026-04-29
CVE-2007-4822 json Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows... Not Provided 2007-09-11 2026-04-23
CVE-2006-5175 json Cross-site request forgery (CSRF) vulnerability in the administrative interface for the TeraStation HD-HTGL firmware 2.05 bet... 7.6 - HIGH 2006-10-10 2017-07-20

Known software with vulnerabilities from Buffalotech

Type Vendor Product Version
HardwareBuffalotechAirstation Extreme N600-
Operating
System
BuffalotechAirstation Extreme N600 Firmware2.09
HardwareBuffalotechAs-100-
ApplicationBuffalotechAs-100 Firmware-
HardwareBuffalotechBbr-4hg-
ApplicationBuffalotechBbr-4hg Firmware-
HardwareBuffalotechBbr-4mg-
ApplicationBuffalotechBbr-4mg Firmware-
HardwareBuffalotechBhr-4grv2-
HardwareBuffalotechBhr-4grv2 Firmware1.03
Operating
System
BuffalotechBhr-4grv2 Firmware1.04
HardwareBuffalotechBhr-4rv-
ApplicationBuffalotechBhr-4rv Firmware-
HardwareBuffalotechFs-g54-
ApplicationBuffalotechFs-g54 Firmware-
HardwareBuffalotechWer-a54g54-
ApplicationBuffalotechWer-a54g54 Firmware-
HardwareBuffalotechWer-ag54-
ApplicationBuffalotechWer-ag54 Firmware-
HardwareBuffalotechWer-am54g54-

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report