First published: Sat Jul 22 2017(Updated: )
Cross-site scripting vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Buffalotech Wmr-433 Firmware | <=1.02 | |
Buffalotech Wmr-433 | ||
Buffalo Wmr-433 Firmware | <=1.40 | |
Buffalo Wmr-433 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-2274 is classified as a high severity vulnerability due to the potential for remote code execution through cross-site scripting.
To mitigate CVE-2017-2274, upgrade to WMR-433 firmware version 1.03 or later and WMR-433W firmware version 1.41 or later.
CVE-2017-2274 affects the Buffalo WMR-433 and WMR-433W devices with firmware versions 1.02 or earlier and 1.40 or earlier, respectively.
CVE-2017-2274 is a cross-site scripting (XSS) vulnerability that allows attackers to inject arbitrary web scripts or HTML.
Yes, CVE-2017-2274 can be exploited remotely by attackers who access the vulnerable firmware.