Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device. The affected products/versions are as follows: WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, and WZR-D1100H firmware Ver. 2.00 and earlier.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Buffalo
Subscribe
|
Hw-450hp-zwe
Subscribe
Hw-450hp-zwe Firmware
Subscribe
Wzr-300hp
Subscribe
Wzr-300hp Firmware
Subscribe
Wzr-450hp
Subscribe
Wzr-450hp-cwt
Subscribe
Wzr-450hp-cwt Firmware
Subscribe
Wzr-450hp-ub
Subscribe
Wzr-450hp-ub Firmware
Subscribe
Wzr-450hp Firmware
Subscribe
Wzr-600dhp
Subscribe
Wzr-600dhp2
Subscribe
Wzr-600dhp2 Firmware
Subscribe
Wzr-600dhp Firmware
Subscribe
Wzr-900dhp
Subscribe
Wzr-900dhp Firmware
Subscribe
Wzr-d1100h
Subscribe
Wzr-d1100h Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-37746 | Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device. The affected products/versions are as follows: WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, and WZR-D1100H firmware Ver. 2.00 and earlier. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Apr 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-04-23T16:10:12.366Z
Reserved: 2022-09-27T00:00:00.000Z
Link: CVE-2022-34840
Updated: 2024-08-03T09:22:10.744Z
Status : Modified
Published: 2022-12-07T10:15:10.303
Modified: 2025-04-23T17:15:48.673
Link: CVE-2022-34840
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD