CVE-2022-34840

MEDIUM

Buffalo Wzr-300hp Firmware < 2.00 - Hard-coded Credentials

Title source: rule
STIX 2.1

Description

Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device. The affected products/versions are as follows: WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, and WZR-D1100H firmware Ver. 2.00 and earlier.

References (2)

Core 2

Scores

CVSS v3 6.5
EPSS 0.0024
EPSS Percentile 15.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (9)
buffalo/hw-450hp-zwe_firmware < 2.00
buffalo/wzr-300hp_firmware < 2.00
buffalo/wzr-450hp-cwt_firmware < 2.00
buffalo/wzr-450hp-ub_firmware < 2.00
buffalo/wzr-450hp_firmware < 2.00
buffalo/wzr-600dhp2_firmware < 1.15
buffalo/wzr-600dhp_firmware < 2.00
buffalo/wzr-900dhp_firmware < 1.15
buffalo/wzr-d1100h_firmware < 2.00
Published Dec 07, 2022
Tracked Since Feb 18, 2026