Security Advisory

CVE-2011-1324

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2011-05-09 19:00:00
Last updated 2024-09-17 03:22:31
Assigner jpcert
CVSS score not scored
State PUBLISHED

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in the management screen on Buffalo WHR, WZR2, WZR, WER, and BBR series routers with firmware 1.x; BHR-4RV and FS-G54 routers with firmware 2.x; and AS-100 routers allow remote attackers to hijack the authentication of administrators for requests that modify settings, as demonstrated by changing the login password.