CVE-2025-46413: Medium severity Buffalo WSR-1800AX4 vulnerability
Use of password hash with insufficient computational effort issue exists in BUFFALO Wi-Fi router 'WSR-1800AX4 series'. When WPS is enabled, PIN code and/or Wi-Fi password may be obtained by an attacker.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46413?
CVE-2025-46413 is considered a high severity vulnerability due to the potential for attackers to easily retrieve sensitive Wi-Fi credentials.
How do I fix CVE-2025-46413?
To mitigate CVE-2025-46413, disable WPS on the BUFFALO WSR-1800AX4 router to prevent unauthorized access to the PIN code and Wi-Fi password.
What systems are affected by CVE-2025-46413?
CVE-2025-46413 specifically affects the BUFFALO WSR-1800AX4 series routers.
What are the risks of leaving WPS enabled on CVE-2025-46413 affected devices?
Leaving WPS enabled on devices affected by CVE-2025-46413 allows attackers to easily retrieve the Wi-Fi password and gain unauthorized access to the network.
Is there a workaround for CVE-2025-46413 if I can't disable WPS?
If disabling WPS is not feasible, consider changing the Wi-Fi password regularly and monitoring your network for unauthorized devices.