CVE-2025-46413: Medium severity Buffalo WSR-1800AX4 vulnerability

Published Nov 7, 2025
·
Updated

Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. When WPS is enabled, PIN code and/or Wi-Fi password may be obtained by an attacker.

Affected Software

1 affected component
Buffalo WSR-1800AX4

Event History

Nov 7, 2025
CVE Published
via MITRE·08:51 AM
Data Sourced
via MITRE·08:51 AM
DescriptionSeverity
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-46413?

CVE-2025-46413 is considered a high severity vulnerability due to the potential for attackers to easily retrieve sensitive Wi-Fi credentials.

2

How do I fix CVE-2025-46413?

To mitigate CVE-2025-46413, disable WPS on the BUFFALO WSR-1800AX4 router to prevent unauthorized access to the PIN code and Wi-Fi password.

3

What systems are affected by CVE-2025-46413?

CVE-2025-46413 specifically affects the BUFFALO WSR-1800AX4 series routers.

4

What are the risks of leaving WPS enabled on CVE-2025-46413 affected devices?

Leaving WPS enabled on devices affected by CVE-2025-46413 allows attackers to easily retrieve the Wi-Fi password and gain unauthorized access to the network.

5

Is there a workaround for CVE-2025-46413 if I can't disable WPS?

If disabling WPS is not feasible, consider changing the Wi-Fi password regularly and monitoring your network for unauthorized devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203