VulnerabilityModified
CVE-2016-7826
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted POST requests.
MEDIUM 6.5EPSS 2.22%
Does this matter?
Lower severity and a low EPSS score (2.22%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted POST requests.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.22% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- buffalotech/wnc01wh firmware
- Source
- vultures@jpcert.or.jp
References
- http://buffalo.jp/support_s/s20161201.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/94648Third Party Advisory, VDB Entry
- https://jvn.jp/en/jp/JVN40613060/index.htmlThird Party Advisory, VDB Entry
- http://buffalo.jp/support_s/s20161201.htmlThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/94648Third Party Advisory, VDB Entry
- https://jvn.jp/en/jp/JVN40613060/index.htmlThird Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.