Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
http://jvn.jp/en/jp/JVN93397125/index.html | third party advisory |
http://buffalo.jp/support_s/s20180328.html | vendor advisory |