CVE-2026-33280

CRITICAL

BUFFALO Wi-Fi router - Command Injection

Title source: llm

Description

Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.

Scores

CVSS v3 9.8
EPSS 0.0009
EPSS Percentile 25.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-912
Status published
Products (47)
buffalo/fs-m1266_firmware < 4.13
buffalo/fs-s1266_firmware < 4.13
buffalo/vr-u300w_firmware < 1.42
buffalo/vr-u500x_firmware < 1.42
buffalo/wapm-1266r_firmware < 1.42
buffalo/wapm-1266wdpra_firmware < 1.42
buffalo/wapm-1266wdpr_firmware < 1.42
buffalo/wapm-1750d_firmware < 1.07
buffalo/wapm-2133r_firmware < 1.42
buffalo/wapm-2133tr_firmware < 1.42
... and 37 more
Published Mar 27, 2026
Tracked Since Mar 27, 2026