Vulnerability Details CVE-2022-40966
Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and access the device. The affected products/versions are as follows: WCR-300 firmware Ver. 1.87 and earlier, WHR-HP-G300N firmware Ver. 2.00 and earlier, WHR-HP-GN firmware Ver. 1.87 and earlier, WPL-05G300 firmware Ver. 1.88 and earlier, WRM-D2133HP firmware Ver. 2.85 and earlier, WRM-D2133HS firmware Ver. 2.96 and earlier, WTR-M2133HP firmware Ver. 2.85 and earlier, WTR-M2133HS firmware Ver. 2.96 and earlier, WXR-1900DHP firmware Ver. 2.50 and earlier, WXR-1900DHP2 firmware Ver. 2.59 and earlier, WXR-1900DHP3 firmware Ver. 2.63 and earlier, WXR-5950AX12 firmware Ver. 3.40 and earlier, WXR-6000AX12B firmware Ver. 3.40 and earlier, WXR-6000AX12S firmware Ver. 3.40 and earlier, WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, WZR-1750DHP2 firmware Ver. 2.31 and earlier, WZR-HP-AG300H firmware Ver. 1.76 and earlier, WZR-HP-G302H firmware Ver. 1.86 and earlier, WEM-1266 firmware Ver. 2.85 and earlier, WEM-1266WP firmware Ver. 2.85 and earlier, WLAE-AG300N firmware Ver. 1.86 and earlier, FS-600DHP firmware Ver. 3.40 and earlier, FS-G300N firmware Ver. 3.14 and earlier, FS-HP-G300N firmware Ver. 3.33 and earlier, FS-R600DHP firmware Ver. 3.40 and earlier, BHR-4GRV firmware Ver. 2.00 and earlier, DWR-HP-G300NH firmware Ver. 1.84 and earlier, DWR-PG firmware Ver. 1.83 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WER-A54G54 firmware Ver. 1.43 and earlier, WER-AG54 firmware Ver. 1.43 and earlier, WER-AM54G54 firmware Ver. 1.43 and earlier, WER-AMG54 firmware Ver. 1.43 and earlier, WHR-300 firmware Ver. 2.00 and earlier, WHR-300HP firmware Ver. 2.00 and earlier, WHR-AM54G54 firmware Ver. 1.43 and earlier, WHR-AMG54 firmware Ver. 1.43 and earlier, WHR-AMPG firmware Ver. 1.52 and earlier, WHR-G firmware Ver. 1.49 and earlier, WHR-G300N firmware Ver. 1.65 and earlier, WHR-G301N firmware Ver. 1.87 and earlier, WHR-G54S firmware Ver. 1.43 and earlier, WHR-G54S-NI firmware Ver. 1.24 and earlier, WHR-HP-AMPG firmware Ver. 1.43 and earlier, WHR-HP-G firmware Ver. 1.49 and earlier, WHR-HP-G54 firmware Ver. 1.43 and earlier, WLI-H4-D600 firmware Ver. 1.88 and earlier, WS024BF firmware Ver. 1.60 and earlier, WS024BF-NW firmware Ver. 1.60 and earlier, WXR-1750DHP firmware Ver. 2.60 and earlier, WXR-1750DHP2 firmware Ver. 2.60 and earlier, WZR-1166DHP firmware Ver. 2.18 and earlier, WZR-1166DHP2 firmware Ver. 2.18 and earlier, WZR-1750DHP firmware Ver. 2.30 and earlier, WZR2-G300N firmware Ver. 1.55 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, WZR-600DHP3 firmware Ver. 2.19 and earlier, WZR-900DHP2 firmware Ver. 2.19 and earlier, WZR-AGL300NH firmware Ver. 1.55 and earlier, WZR-AMPG144NH firmware Ver. 1.49 and earlier, WZR-AMPG300NH firmware Ver. 1.51 and earlier, WZR-D1100H firmware Ver. 2.00 and earlier, WZR-G144N firmware Ver. 1.48 and earlier, WZR-G144NH firmware Ver. 1.48 and earlier, WZR-HP-G300NH firmware Ver. 1.84 and earlier, WZR-HP-G301NH firmware Ver. 1.84 and earlier, WZR-HP-G450H firmware Ver. 1.90 and earlier, WZR-S1750DHP firmware Ver. 2.32 and earlier, WZR-S600DHP firmware Ver. 2.19 and earlier, and WZR-S900DHP firmware Ver. 2.19 and earlier.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 5.5%
CVSS Severity
CVSS v3 Score 8.8
Products affected by CVE-2022-40966
-
cpe:2.3:h:buffalo:bhr-4grv:-
-
cpe:2.3:h:buffalo:dwr-hp-g300nh:-
-
cpe:2.3:h:buffalo:dwr-pg:-
-
cpe:2.3:h:buffalo:fs-600dhp:-
-
cpe:2.3:h:buffalo:fs-g300n:-
-
cpe:2.3:h:buffalo:fs-hp-g300n:-
-
cpe:2.3:h:buffalo:fs-r600dhp:-
-
cpe:2.3:h:buffalo:hw-450hp-zwe:-
-
cpe:2.3:h:buffalo:wcr-300:-
-
cpe:2.3:h:buffalo:wem-1266:-
-
cpe:2.3:h:buffalo:wem-1266wp:-
-
cpe:2.3:h:buffalo:wer-a54g54:-
-
cpe:2.3:h:buffalo:wer-ag54:-
-
cpe:2.3:h:buffalo:wer-am54g54:-
-
cpe:2.3:h:buffalo:wer-amg54:-
-
cpe:2.3:h:buffalo:whr-300:-
-
cpe:2.3:h:buffalo:whr-300hp:-
-
cpe:2.3:h:buffalo:whr-am54g54:-
-
cpe:2.3:h:buffalo:whr-amg54:-
-
cpe:2.3:h:buffalo:whr-ampg:-
-
cpe:2.3:h:buffalo:whr-g300n:-
-
cpe:2.3:h:buffalo:whr-g301n:-
-
cpe:2.3:h:buffalo:whr-g54s-ni:-
-
cpe:2.3:h:buffalo:whr-g54s:-
-
cpe:2.3:h:buffalo:whr-g:-
-
cpe:2.3:h:buffalo:whr-hp-ampg:-
-
cpe:2.3:h:buffalo:whr-hp-g300n:-
-
cpe:2.3:h:buffalo:whr-hp-g54:-
-
cpe:2.3:h:buffalo:whr-hp-g:-
-
cpe:2.3:h:buffalo:whr-hp-gn:-
-
cpe:2.3:h:buffalo:wlae-ag300n:-
-
cpe:2.3:h:buffalo:wli-h4-d600:-
-
cpe:2.3:h:buffalo:wpl-05g300:-
-
cpe:2.3:h:buffalo:wrm-d2133hp:-
-
cpe:2.3:h:buffalo:wrm-d2133hs:-
-
cpe:2.3:h:buffalo:ws024bf-nw:-
-
cpe:2.3:h:buffalo:ws024bf:-
-
cpe:2.3:h:buffalo:wtr-m2133hp:-
-
cpe:2.3:h:buffalo:wtr-m2133hs:-
-
cpe:2.3:h:buffalo:wxr-1750dhp2:-
-
cpe:2.3:h:buffalo:wxr-1750dhp:-
-
cpe:2.3:h:buffalo:wxr-1900dhp2:-
-
cpe:2.3:h:buffalo:wxr-1900dhp3:-
-
cpe:2.3:h:buffalo:wxr-1900dhp:-
-
cpe:2.3:h:buffalo:wxr-5950ax12:-
-
cpe:2.3:h:buffalo:wxr-6000ax12b:-
-
cpe:2.3:h:buffalo:wxr-6000ax12s:-
-
cpe:2.3:h:buffalo:wzr-1166dhp2:-
-
cpe:2.3:h:buffalo:wzr-1166dhp:-
-
cpe:2.3:h:buffalo:wzr-1750dhp2:-
-
cpe:2.3:h:buffalo:wzr-1750dhp:-
-
cpe:2.3:h:buffalo:wzr-300hp:-
-
cpe:2.3:h:buffalo:wzr-450hp-cwt:-
-
cpe:2.3:h:buffalo:wzr-450hp-ub:-
-
cpe:2.3:h:buffalo:wzr-450hp:-
-
cpe:2.3:h:buffalo:wzr-600dhp2:-
-
cpe:2.3:h:buffalo:wzr-600dhp3:-
-
cpe:2.3:h:buffalo:wzr-600dhp:-
-
cpe:2.3:h:buffalo:wzr-900dhp2:-
-
cpe:2.3:h:buffalo:wzr-900dhp:-
-
cpe:2.3:h:buffalo:wzr-agl300nh:-
-
cpe:2.3:h:buffalo:wzr-ampg144nh:-
-
cpe:2.3:h:buffalo:wzr-ampg300nh:-
-
cpe:2.3:h:buffalo:wzr-d1100h:-
-
cpe:2.3:h:buffalo:wzr-g144n:-
-
cpe:2.3:h:buffalo:wzr-g144nh:-
-
cpe:2.3:h:buffalo:wzr-hp-ag300h:-
-
cpe:2.3:h:buffalo:wzr-hp-g300nh:-
-
cpe:2.3:h:buffalo:wzr-hp-g301nh:-
-
cpe:2.3:h:buffalo:wzr-hp-g302h:-
-
cpe:2.3:h:buffalo:wzr-hp-g450h:-
-
cpe:2.3:h:buffalo:wzr-s1750dhp:-
-
cpe:2.3:h:buffalo:wzr-s600dhp:-
-
cpe:2.3:h:buffalo:wzr-s900dhp:-
-
cpe:2.3:h:buffalo:wzr2-g300n:-
-
cpe:2.3:o:buffalo:bhr-4grv_firmware:-
-
cpe:2.3:o:buffalo:bhr-4grv_firmware:1.96
-
cpe:2.3:o:buffalo:bhr-4grv_firmware:1.99
-
cpe:2.3:o:buffalo:bhr-4grv_firmware:2.00
-
cpe:2.3:o:buffalo:dwr-hp-g300nh_firmware:-
-
cpe:2.3:o:buffalo:dwr-hp-g300nh_firmware:1.81
-
cpe:2.3:o:buffalo:dwr-hp-g300nh_firmware:1.83
-
cpe:2.3:o:buffalo:dwr-hp-g300nh_firmware:1.84
-
cpe:2.3:o:buffalo:dwr-pg_firmware:-
-
cpe:2.3:o:buffalo:dwr-pg_firmware:1.83
-
cpe:2.3:o:buffalo:fs-600dhp_firmware:-
-
cpe:2.3:o:buffalo:fs-600dhp_firmware:3.34
-
cpe:2.3:o:buffalo:fs-600dhp_firmware:3.39
-
cpe:2.3:o:buffalo:fs-600dhp_firmware:3.40
-
cpe:2.3:o:buffalo:fs-g300n_firmware:-
-
cpe:2.3:o:buffalo:fs-g300n_firmware:3.13
-
cpe:2.3:o:buffalo:fs-g300n_firmware:3.14
-
cpe:2.3:o:buffalo:fs-hp-g300n_firmware:-
-
cpe:2.3:o:buffalo:fs-hp-g300n_firmware:3.32
-
cpe:2.3:o:buffalo:fs-hp-g300n_firmware:3.33
-
cpe:2.3:o:buffalo:fs-r600dhp_firmware:-
-
cpe:2.3:o:buffalo:fs-r600dhp_firmware:3.39
-
cpe:2.3:o:buffalo:fs-r600dhp_firmware:3.40
-
cpe:2.3:o:buffalo:hw-450hp-zwe_firmware:-
-
cpe:2.3:o:buffalo:hw-450hp-zwe_firmware:1.91
-
cpe:2.3:o:buffalo:hw-450hp-zwe_firmware:1.99
-
cpe:2.3:o:buffalo:hw-450hp-zwe_firmware:2.00
-
cpe:2.3:o:buffalo:wcr-300_firmware:1.86
-
cpe:2.3:o:buffalo:wcr-300_firmware:1.87
-
cpe:2.3:o:buffalo:wem-1266_firmware:-
-
cpe:2.3:o:buffalo:wem-1266_firmware:2.85
-
cpe:2.3:o:buffalo:wem-1266wp_firmware:-
-
cpe:2.3:o:buffalo:wem-1266wp_firmware:2.85
-
cpe:2.3:o:buffalo:wer-a54g54_firmware:-
-
cpe:2.3:o:buffalo:wer-a54g54_firmware:1.43
-
cpe:2.3:o:buffalo:wer-ag54_firmware:-
-
cpe:2.3:o:buffalo:wer-am54g54_firmware:-
-
cpe:2.3:o:buffalo:wer-amg54_firmware:-
-
cpe:2.3:o:buffalo:whr-300_firmware:-
-
cpe:2.3:o:buffalo:whr-300_firmware:1.96
-
cpe:2.3:o:buffalo:whr-300_firmware:1.99
-
cpe:2.3:o:buffalo:whr-300_firmware:2.00
-
cpe:2.3:o:buffalo:whr-300hp_firmware:-
-
cpe:2.3:o:buffalo:whr-300hp_firmware:1.96
-
cpe:2.3:o:buffalo:whr-300hp_firmware:1.99
-
cpe:2.3:o:buffalo:whr-300hp_firmware:2.00
-
cpe:2.3:o:buffalo:whr-am54g54_firmware:-
-
cpe:2.3:o:buffalo:whr-amg54_firmware:-
-
cpe:2.3:o:buffalo:whr-ampg_firmware:-
-
cpe:2.3:o:buffalo:whr-g300n_firmware:-
-
cpe:2.3:o:buffalo:whr-g301n_firmware:-
-
cpe:2.3:o:buffalo:whr-g301n_firmware:1.86
-
cpe:2.3:o:buffalo:whr-g301n_firmware:1.87
-
cpe:2.3:o:buffalo:whr-g54s-ni_firmware:-
-
cpe:2.3:o:buffalo:whr-g54s_firmware:-
-
cpe:2.3:o:buffalo:whr-g_firmware:-
-
cpe:2.3:o:buffalo:whr-hp-ampg_firmware:-
-
cpe:2.3:o:buffalo:whr-hp-g300n_firmware:-
-
cpe:2.3:o:buffalo:whr-hp-g300n_firmware:1.96
-
cpe:2.3:o:buffalo:whr-hp-g300n_firmware:1.99
-
cpe:2.3:o:buffalo:whr-hp-g300n_firmware:2.00
-
cpe:2.3:o:buffalo:whr-hp-g54_firmware:-
-
cpe:2.3:o:buffalo:whr-hp-g_firmware:-
-
cpe:2.3:o:buffalo:whr-hp-gn_firmware:-
-
cpe:2.3:o:buffalo:whr-hp-gn_firmware:1.86
-
cpe:2.3:o:buffalo:whr-hp-gn_firmware:1.87
-
cpe:2.3:o:buffalo:wlae-ag300n_firmware:-
-
cpe:2.3:o:buffalo:wli-h4-d600_firmware:-
-
cpe:2.3:o:buffalo:wpl-05g300_firmware:-
-
cpe:2.3:o:buffalo:wpl-05g300_firmware:1.86
-
cpe:2.3:o:buffalo:wpl-05g300_firmware:1.87
-
cpe:2.3:o:buffalo:wpl-05g300_firmware:1.88
-
cpe:2.3:o:buffalo:wrm-d2133hp_firmware:-
-
cpe:2.3:o:buffalo:wrm-d2133hs_firmware:-
-
cpe:2.3:o:buffalo:ws024bf-nw_firmware:-
-
cpe:2.3:o:buffalo:ws024bf_firmware:-
-
cpe:2.3:o:buffalo:wtr-m2133hp_firmware:-
-
cpe:2.3:o:buffalo:wtr-m2133hs_firmware:-
-
cpe:2.3:o:buffalo:wxr-1750dhp2_firmware:-
-
cpe:2.3:o:buffalo:wxr-1750dhp_firmware:2.42
-
cpe:2.3:o:buffalo:wxr-1900dhp2_firmware:2.48
-
cpe:2.3:o:buffalo:wxr-1900dhp3_firmware:-
-
cpe:2.3:o:buffalo:wxr-1900dhp_firmware:2.34
-
cpe:2.3:o:buffalo:wxr-5950ax12_firmware:-
-
cpe:2.3:o:buffalo:wxr-6000ax12b_firmware:-
-
cpe:2.3:o:buffalo:wxr-6000ax12s_firmware:-
-
cpe:2.3:o:buffalo:wzr-1166dhp2_firmware:2.13
-
cpe:2.3:o:buffalo:wzr-1166dhp_firmware:2.13
-
cpe:2.3:o:buffalo:wzr-1750dhp2_firmware:2.28
-
cpe:2.3:o:buffalo:wzr-1750dhp2_firmware:2.30
-
cpe:2.3:o:buffalo:wzr-1750dhp_firmware:2.28
-
cpe:2.3:o:buffalo:wzr-300hp_firmware:-
-
cpe:2.3:o:buffalo:wzr-300hp_firmware:1.96
-
cpe:2.3:o:buffalo:wzr-300hp_firmware:1.99
-
cpe:2.3:o:buffalo:wzr-300hp_firmware:2.00
-
cpe:2.3:o:buffalo:wzr-450hp-cwt_firmware:-
-
cpe:2.3:o:buffalo:wzr-450hp-cwt_firmware:1.92
-
cpe:2.3:o:buffalo:wzr-450hp-cwt_firmware:1.99
-
cpe:2.3:o:buffalo:wzr-450hp-cwt_firmware:2.00
-
cpe:2.3:o:buffalo:wzr-450hp-ub_firmware:-
-
cpe:2.3:o:buffalo:wzr-450hp-ub_firmware:1.96
-
cpe:2.3:o:buffalo:wzr-450hp-ub_firmware:1.99
-
cpe:2.3:o:buffalo:wzr-450hp-ub_firmware:2.00
-
cpe:2.3:o:buffalo:wzr-450hp_firmware:-
-
cpe:2.3:o:buffalo:wzr-450hp_firmware:1.97
-
cpe:2.3:o:buffalo:wzr-450hp_firmware:1.99
-
cpe:2.3:o:buffalo:wzr-450hp_firmware:2.00
-
cpe:2.3:o:buffalo:wzr-600dhp2_firmware:1.13
-
cpe:2.3:o:buffalo:wzr-600dhp3_firmware:2.16
-
cpe:2.3:o:buffalo:wzr-600dhp_firmware:-
-
cpe:2.3:o:buffalo:wzr-600dhp_firmware:1.97
-
cpe:2.3:o:buffalo:wzr-600dhp_firmware:1.99
-
cpe:2.3:o:buffalo:wzr-600dhp_firmware:2.00
-
cpe:2.3:o:buffalo:wzr-900dhp2_firmware:1.13
-
cpe:2.3:o:buffalo:wzr-900dhp2_firmware:2.16
-
cpe:2.3:o:buffalo:wzr-900dhp_firmware:1.11
-
cpe:2.3:o:buffalo:wzr-agl300nh_firmware:-
-
cpe:2.3:o:buffalo:wzr-ampg144nh_firmware:-
-
cpe:2.3:o:buffalo:wzr-ampg300nh_firmware:-
-
cpe:2.3:o:buffalo:wzr-d1100h_firmware:-
-
cpe:2.3:o:buffalo:wzr-d1100h_firmware:1.96
-
cpe:2.3:o:buffalo:wzr-d1100h_firmware:1.99
-
cpe:2.3:o:buffalo:wzr-d1100h_firmware:2.00
-
cpe:2.3:o:buffalo:wzr-g144n_firmware:-
-
cpe:2.3:o:buffalo:wzr-g144nh_firmware:-
-
cpe:2.3:o:buffalo:wzr-hp-ag300h_firmware:-
-
cpe:2.3:o:buffalo:wzr-hp-ag300h_firmware:1.73
-
cpe:2.3:o:buffalo:wzr-hp-ag300h_firmware:1.75
-
cpe:2.3:o:buffalo:wzr-hp-ag300h_firmware:1.76
-
cpe:2.3:o:buffalo:wzr-hp-g300nh_firmware:-
-
cpe:2.3:o:buffalo:wzr-hp-g300nh_firmware:1.81
-
cpe:2.3:o:buffalo:wzr-hp-g300nh_firmware:1.83
-
cpe:2.3:o:buffalo:wzr-hp-g300nh_firmware:1.84
-
cpe:2.3:o:buffalo:wzr-hp-g301nh_firmware:-
-
cpe:2.3:o:buffalo:wzr-hp-g301nh_firmware:1.81
-
cpe:2.3:o:buffalo:wzr-hp-g301nh_firmware:1.83
-
cpe:2.3:o:buffalo:wzr-hp-g301nh_firmware:1.84
-
cpe:2.3:o:buffalo:wzr-hp-g302h_firmware:-
-
cpe:2.3:o:buffalo:wzr-hp-g302h_firmware:1.83
-
cpe:2.3:o:buffalo:wzr-hp-g302h_firmware:1.85
-
cpe:2.3:o:buffalo:wzr-hp-g302h_firmware:1.86
-
cpe:2.3:o:buffalo:wzr-hp-g450h_firmware:-
-
cpe:2.3:o:buffalo:wzr-hp-g450h_firmware:1.87
-
cpe:2.3:o:buffalo:wzr-hp-g450h_firmware:1.89
-
cpe:2.3:o:buffalo:wzr-hp-g450h_firmware:1.90
-
cpe:2.3:o:buffalo:wzr-s1750dhp_firmware:2.28
-
cpe:2.3:o:buffalo:wzr-s600dhp_firmware:2.16
-
cpe:2.3:o:buffalo:wzr-s900dhp_firmware:2.16
-
cpe:2.3:o:buffalo:wzr2-g300n_firmware:-