|
[Japanese]
|
JVNDB-2026-035794
|
Multiple vulnerabilities in BUFFALO Wi-Fi Products
|
The web configuration user interfaces of Wi-Fi products provided by BUFFALO INC. contain multiple vulnerabilities listed below.- OS command injection (CWE-78) - CVE-2026-86530
- Stack-based buffer overflow (CWE-121) - CVE-2026-95104
Veeti Punnonen reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.
|
CVSS V3 Severity: Base Metrics 7.2 (High) [Other]
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
The above CVSS base scores have been assigned for CVE-2026-86530 |
CVSS v3 Severity Base Metrics:7.5 (High) [Other]- Access Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Confidentiality Impact(C): None
- Integrity Impact(I): None
- Availability Impact(A): High
The above CVSS base scores have been assigned for CVE-2026-95104
|
|
BUFFALO INC.
- WEX-G300 firmware versions prior to Ver.1.71
- WSR-300HP firmware versions prior to Ver.2.55
|
|
- An administrative user may send a crafted HTTP request and execute an arbitrary OS command (CVE-2026-86530).
- A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition (CVE-2026-95104).
|
[Update the firmware]
Update the firmware to the latest version according to the information provided by the developer.
The fixed versions are provided on the following date: - WSR-300HP firmware Ver.2.55, August 25, 2026
- WEX-G300 firmware Ver.1.71, September 3, 2026
The affected products may be automatically updated if "automatic firmware update" feature is enabled.
|
BUFFALO INC.
|
- Stack-based Buffer Overflow(CWE-121) [Other]
- OS Command Injection(CWE-78) [Other]
|
- CVE-2026-86530
- CVE-2026-95104
|
- JVN : JVNVU#94863997
|
- [2026/09/29]
Web page was published
|