CVE-2007-4822
Buffalotech Airstation Whr-g54s - CSRF
Title source: ruleDescription
Cross-site request forgery (CSRF) vulnerability in the device management interface in Buffalo AirStation WHR-G54S 1.20 allows remote attackers to make configuration changes as an administrator via HTTP requests to certain HTML pages in the res parameter with an inp req parameter to cgi-bin/cgi, as demonstrated by accessing (1) ap.html and (2) filter_ip.html.
References (8)
Scores
EPSS
0.0040
EPSS Percentile
60.5%
Classification
CWE
CWE-352
Status
draft
Affected Products (1)
buffalotech/airstation_whr-g54s
Timeline
Published
Sep 11, 2007
Tracked Since
Feb 18, 2026