CVE-2016-4815: Buffalo Wzr-600dhp2 Firmware

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

Directory traversal vulnerability on BUFFALO WZR-600DHP3 devices with firmware 2.16 and earlier and WZR-S600DHP devices with firmware 2.16 and earlier allows remote attackers to read arbitrary files via unspecified vectors.

Affected products

  • Buffalo Wzr-600dhp2 Firmware: up to and including 1.13
  • Buffalo Wzr-600dhp3 Firmware: up to and including 2.16
  • Buffalo Wzr-900dhp2 Firmware: up to and including 2.16
  • Buffalo Wzr-900dhp Firmware: up to and including 1.11
  • Buffalo Wzr-s600dhp Firmware: up to and including 2.16
  • Buffalo Wzr-s900dhp Firmware: up to and including 2.16

Published 2016-06-19. Last modified 2026-06-17.