CVE-2026-33280

CRITICAL

BUFFALO Wi-Fi router - Command Injection

Title source: llm
STIX 2.1

Description

Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.

Scores

CVSS v3 9.8
EPSS 0.0038
EPSS Percentile 29.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-912
Status published
Products (47)
buffalo/fs-m1266_firmware < 4.13
buffalo/fs-s1266_firmware < 4.13
buffalo/vr-u300w_firmware < 1.42
buffalo/vr-u500x_firmware < 1.42
buffalo/wapm-1266r_firmware < 1.42
buffalo/wapm-1266wdpr_firmware < 1.42
buffalo/wapm-1266wdpra_firmware < 1.42
buffalo/wapm-1750d_firmware < 1.07
buffalo/wapm-2133r_firmware < 1.42
buffalo/wapm-2133tr_firmware < 1.42
... and 37 more
Published Mar 27, 2026
Tracked Since Mar 27, 2026