CVE-2017-2273: CSRF
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2273?
CVE-2017-2273 has a high severity as it allows remote attackers to perform cross-site request forgery attacks that can hijack administrator authentication.
How do I fix CVE-2017-2273?
To fix CVE-2017-2273, upgrade your firmware to versions later than 1.02 for WMR-433 or later than 1.40 for WMR-433W.
What types of devices are affected by CVE-2017-2273?
CVE-2017-2273 affects Buffalo WMR-433 and WMR-433W devices running vulnerable firmware versions.
Can CVE-2017-2273 be exploited remotely?
Yes, CVE-2017-2273 can be exploited remotely by attackers who can send deceptive requests to the affected firmware.
What is cross-site request forgery in the context of CVE-2017-2273?
Cross-site request forgery in the context of CVE-2017-2273 refers to an attack where an unauthorized command is performed on behalf of an authenticated user.