CVE-2026-27650
HIGH EPSS 55.8%
Published Mar 27, 20263mo ago · Modified Jun 17, 20261w ago
8.6 CVSS 4.0
Published Mar 27, 2026 3mo ago
Last Modified Jun 17, 2026 1w ago
Description
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction A
Scope X
Threat Intelligence
EPSS Exploit Probability
55.8% percentile
Exploit & Patch Status
No Known Exploit
No Patch Available
Weaknesses 1
CWE-78 OS Command Injection Injection
Affected Products 92
| Vendor | Product | Version | Range |
|---|---|---|---|
| buffalo | wcr-1166dhpl_firmware | * | <1.01 |
| buffalo | wcr-1166dhpl | * | any |
| buffalo | wsr3600be4-kh_firmware | * | <6.02 |
| buffalo | wsr3600be4-kh | * | any |
| buffalo | wsr3600be4p_firmware | * | <5.02 |
| buffalo | wsr3600be4p | * | any |
| buffalo | wxr-1750dhp_firmware | * | <2.63 |
| buffalo | wxr-1750dhp | * | any |
| buffalo | wxr-1750dhp2_firmware | * | <2.63 |
| buffalo | wxr-1750dhp2 | * | any |
| buffalo | wxr18000be10p_firmware | * | <5.03 |
| buffalo | wxr18000be10p | * | any |
| buffalo | wxr-1900dhp_firmware | * | <2.53 |
| buffalo | wxr-1900dhp | * | any |
| buffalo | wxr-1900dhp2_firmware | * | <2.62 |
| buffalo | wxr-1900dhp2 | * | any |
| buffalo | wxr-1900dhp3_firmware | * | <2.66 |
| buffalo | wxr-1900dhp3 | * | any |
| buffalo | wxr-5950ax12_firmware | * | <3.57 |
| buffalo | wxr-5950ax12 | * | any |
| buffalo | wxr-6000ax12b_firmware | * | <3.57 |
| buffalo | wxr-6000ax12b | * | any |
| buffalo | wxr-6000ax12p_firmware | * | <3.57 |
| buffalo | wxr-6000ax12p | * | any |
| buffalo | wxr-6000ax12s_firmware | * | <3.57 |
| buffalo | wxr-6000ax12s | * | any |
| buffalo | wzr-1166dhp_firmware | * | <2.20 |
| buffalo | wzr-1166dhp | * | any |
| buffalo | wzr-1166dhp2_firmware | * | <2.20 |
| buffalo | wzr-1166dhp2 | * | any |
| buffalo | wzr-1750dhp_firmware | * | <2.32 |
| buffalo | wzr-1750dhp | * | any |
| buffalo | wzr-1750dhp2_firmware | * | <2.33 |
| buffalo | wzr-1750dhp2 | * | any |
| buffalo | wzr-s1750dhp_firmware | * | <2.34 |
| buffalo | wzr-s1750dhp | * | any |
| buffalo | wrm-d2133hp_firmware | * | <3.01 |
| buffalo | wrm-d2133hp | * | any |
| buffalo | wrm-d2133hs_firmware | * | <3.01 |
| buffalo | wrm-d2133hs | * | any |
| buffalo | wtr-m2133hp_firmware | * | <3.01 |
| buffalo | wtr-m2133hp | * | any |
| buffalo | wtr-m2133hs_firmware | * | <3.01 |
| buffalo | wtr-m2133hs | * | any |
| buffalo | wem-1266_firmware | * | <2.87 |
| buffalo | wem-1266 | * | any |
| buffalo | wem-1266wp_firmware | * | <2.87 |
| buffalo | wem-1266wp | * | any |
| buffalo | vr-u300w_firmware | * | <1.42 |
| buffalo | vr-u300w | * | any |
| buffalo | vr-u500x_firmware | * | <1.42 |
| buffalo | vr-u500x | * | any |
| buffalo | wapm-1266r_firmware | * | <1.42 |
| buffalo | wapm-1266r | * | any |
| buffalo | wapm-1266wdpr_firmware | * | <1.42 |
| buffalo | wapm-1266wdpr | * | any |
| buffalo | wapm-1266wdpra_firmware | * | <1.42 |
| buffalo | wapm-1266wdpra | * | any |
| buffalo | wapm-1750d_firmware | * | <1.07 |
| buffalo | wapm-1750d | * | any |
| buffalo | wapm-2133r_firmware | * | <1.42 |
| buffalo | wapm-2133r | * | any |
| buffalo | wapm-2133tr_firmware | * | <1.42 |
| buffalo | wapm-2133tr | * | any |
| buffalo | wapm-ax4r_firmware | * | <1.42 |
| buffalo | wapm-ax4r | * | any |
| buffalo | wapm-ax8r_firmware | * | <1.42 |
| buffalo | wapm-ax8r | * | any |
| buffalo | wapm-axetr_firmware | * | <1.42 |
| buffalo | wapm-axetr | * | any |
| buffalo | waps-1266_firmware | * | <1.42 |
| buffalo | waps-1266 | * | any |
| buffalo | waps-ax4_firmware | * | <1.42 |
| buffalo | waps-ax4 | * | any |
| buffalo | fs-m1266_firmware | * | <4.13 |
| buffalo | fs-m1266 | * | any |
| buffalo | fs-s1266_firmware | * | <4.13 |
| buffalo | fs-s1266 | * | any |
| buffalo | wzr-600dhp_firmware | * | any |
| buffalo | wzr-600dhp | * | any |
| buffalo | wzr-600dhp2_firmware | * | any |
| buffalo | wzr-600dhp2 | * | any |
| buffalo | wzr-600dhp3_firmware | * | any |
| buffalo | wzr-600dhp3 | * | any |
| buffalo | wzr-900dhp_firmware | * | any |
| buffalo | wzr-900dhp | * | any |
| buffalo | wzr-900dhp2_firmware | * | any |
| buffalo | wzr-900dhp2 | * | any |
| buffalo | wzr-s600dhp_firmware | * | any |
| buffalo | wzr-s600dhp | * | any |
| buffalo | wzr-s900dhp_firmware | * | any |
| buffalo | wzr-s900dhp | * | any |
References 2
- jvn.jp https://jvn.jp/en/jp/JVN83788689/
- buffalo.jp https://www.buffalo.jp/news/detail/20260323-01.html
Remediation
No remediation data recorded yet
Check vendor advisories and the NVD entry for patch availability.