Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 14 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Buffaloamericas
Buffaloamericas terastation Nas Ts5400r Buffaloamericas terastation Nas Ts5400r Firmware |
|
| CPEs | cpe:2.3:h:buffaloamericas:terastation_nas_ts5400r:-:*:*:*:*:*:*:* cpe:2.3:o:buffaloamericas:terastation_nas_ts5400r_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Buffaloamericas
Buffaloamericas terastation Nas Ts5400r Buffaloamericas terastation Nas Ts5400r Firmware |
Tue, 17 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 17 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Buffalo
Buffalo terastation Nas Ts5400r |
|
| Vendors & Products |
Buffalo
Buffalo terastation Nas Ts5400r |
Mon, 16 Mar 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Mar 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Buffalo TeraStation NAS TS5400R firmware version 4.02-0.06 and prior contain an excessive file permissions vulnerability that allows authenticated attackers to read the /etc/shadow file by uploading and executing a PHP file through the webserver. Attackers can exploit world-readable permissions on /etc/shadow to retrieve hashed passwords for all configured accounts including root. | |
| Title | Buffalo TeraStation TS5400R Excessive File Permissions Information Disclosure | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-11T23:11:43.348Z
Reserved: 2026-03-04T15:39:26.872Z
Link: CVE-2026-29516
Updated: 2026-03-16T20:08:33.673Z
Status : Analyzed
Published: 2026-03-16T20:16:18.113
Modified: 2026-05-14T20:23:29.717
Link: CVE-2026-29516
No data.
OpenCVE Enrichment
Updated: 2026-03-24T10:49:55Z