A vulnerability described as problematic has been identified in BUFFALO WSR-1800AX4, WSR-1800AX4S, WSR-1800AX4B and WSR-1800AX4-KH. This affects an unknown function. Executing manipulation can lead to password hash with insufficient computational effort.
The identification of this vulnerability is CVE-2025-46413. The attack needs to be done within the local network. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability marked as critical has been reported in DIAL CentrosNet up to 2.64. The impacted element is an unknown function of the file /centrosnet/ultralogin.php. Performing manipulation of the argument ultralogin results in sql injection.
This vulnerability was named CVE-2025-10870. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.