CVE-2022-34840
MEDIUMBuffalo Wzr-300hp Firmware < 2.00 - Hard-coded Credentials
Title source: ruleDescription
Use of hard-coded credentials vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to alter?configuration settings of the device. The affected products/versions are as follows: WZR-300HP firmware Ver. 2.00 and earlier, WZR-450HP firmware Ver. 2.00 and earlier, WZR-600DHP firmware Ver. 2.00 and earlier, WZR-900DHP firmware Ver. 1.15 and earlier, HW-450HP-ZWE firmware Ver. 2.00 and earlier, WZR-450HP-CWT firmware Ver. 2.00 and earlier, WZR-450HP-UB firmware Ver. 2.00 and earlier, WZR-600DHP2 firmware Ver. 1.15 and earlier, and WZR-D1100H firmware Ver. 2.00 and earlier.
References (2)
Core 2
Core References
Third Party Advisory
https://jvn.jp/en/vu/JVNVU92805279/index.html
Patch, Vendor Advisory
https://www.buffalo.jp/news/detail/20221003-01.html
Scores
CVSS v3
6.5
EPSS
0.0024
EPSS Percentile
15.1%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-798
Status
published
Products (9)
buffalo/hw-450hp-zwe_firmware
< 2.00
buffalo/wzr-300hp_firmware
< 2.00
buffalo/wzr-450hp-cwt_firmware
< 2.00
buffalo/wzr-450hp-ub_firmware
< 2.00
buffalo/wzr-450hp_firmware
< 2.00
buffalo/wzr-600dhp2_firmware
< 1.15
buffalo/wzr-600dhp_firmware
< 2.00
buffalo/wzr-900dhp_firmware
< 1.15
buffalo/wzr-d1100h_firmware
< 2.00
Published
Dec 07, 2022
Tracked Since
Feb 18, 2026