First published: Fri Jan 22 2016(Updated: )
Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WHR-600D devices with firmware 1.90 and earlier, WMR-300 devices with firmware 1.90 and earlier, WMR-433 devices with firmware 1.01 and earlier, and WSR-1166DHP devices with firmware 1.01 and earlier allows remote attackers to hijack the authentication of arbitrary users.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Buffalotech WHR-1166DHP | ||
Buffalotech WHR-1166DHP Firmware | <=1.90 | |
Buffalotech Whr-300hp2 Firmware | ||
Buffalotech Whr-300hp2 Firmware | <=1.90 | |
Buffalotech Wmr-300 | ||
Buffalotech Wmr-300 | <=1.90 | |
Buffalotech Bhr-4grv2 Firmware | ||
Buffalo BHR-4GRV2 | <=1.04 | |
Buffalotech Wex-300 Firmware | ||
Buffalotech Wex-300 | <=1.90 | |
Buffalotech WHR-600D Firmware | ||
Buffalotech WHR-600D Firmware | <=1.90 | |
Buffalotech Wmr-433 Firmware | ||
Buffalo Wmr-433 Firmware | <=1.01 | |
Buffalotech Wsr-1166dhp Firmware | ||
Buffalotech WHR-1166DHP Firmware | <=1.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1134 has been rated as a medium severity vulnerability due to the risk of cross-site request forgery.
To fix CVE-2016-1134, update the firmware on your affected Buffalo devices to the latest version beyond the specified vulnerable firmware versions.
CVE-2016-1134 affects Buffalo BHR-4GRV2, WEX-300, WHR-1166DHP, WHR-300HP2, and WHR-600D devices with specific firmware versions.
Yes, CVE-2016-1134 can potentially be exploited remotely, allowing an attacker to perform unauthorized actions on behalf of the user.
If updating is not possible, limiting access to the devices and employing additional network security measures can help mitigate the risk of CVE-2016-1134.