CVE-2026-33280
CRITICALBUFFALO Wi-Fi router - Command Injection
Title source: llmDescription
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.
Scores
CVSS v3
9.8
EPSS
0.0009
EPSS Percentile
25.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-912
Status
published
Products (47)
buffalo/fs-m1266_firmware
< 4.13
buffalo/fs-s1266_firmware
< 4.13
buffalo/vr-u300w_firmware
< 1.42
buffalo/vr-u500x_firmware
< 1.42
buffalo/wapm-1266r_firmware
< 1.42
buffalo/wapm-1266wdpra_firmware
< 1.42
buffalo/wapm-1266wdpr_firmware
< 1.42
buffalo/wapm-1750d_firmware
< 1.07
buffalo/wapm-2133r_firmware
< 1.42
buffalo/wapm-2133tr_firmware
< 1.42
... and 37 more
Published
Mar 27, 2026
Tracked Since
Mar 27, 2026