First published: Fri Dec 08 2017(Updated: )
Cross-site scripting vulnerability in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Arcadyan Buffalo Firmware | >=1.00<=1.48 | |
Arcadyan Buffalo Firmware | >=2.00<=2.07 | |
Buffalo BBR-4MG Firmware | ||
Buffalo BBR-4HG firmware | >=1.00<=1.48 | |
Buffalo BBR-4HG firmware | >=2.00<=2.07 | |
Buffalo BBR-4HG firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-10896 is Medium with a severity value of 6.1.
The affected software of CVE-2017-10896 is Buffalo BBR-4HG and BBR-4MG broadband routers with firmware versions 1.00 to 1.48 and 2.00 to 2.07.
An attacker can exploit CVE-2017-10896 by injecting arbitrary web script or HTML via unspecified vectors in Buffalo BBR-4HG and BBR-4MG broadband routers with vulnerable firmware versions.
Yes, Buffalo BBR-4MG with firmware versions 1.00 to 1.48 and 2.00 to 2.07 is vulnerable to CVE-2017-10896.
Yes, the fix for CVE-2017-10896 can be found on the Buffalo support website.