9.8

CVE-2026-33280

Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BuffaloWcr-1166dhpl Firmware Version < 1.01
   BuffaloWcr-1166dhpl Version-
BuffaloWsr3600be4-kh Firmware Version < 6.02
   BuffaloWsr3600be4-kh Version-
BuffaloWsr3600be4p Firmware Version < 5.02
   BuffaloWsr3600be4p Version-
BuffaloWxr-1750dhp Firmware Version < 2.63
   BuffaloWxr-1750dhp Version-
BuffaloWxr-1750dhp2 Firmware Version < 2.63
   BuffaloWxr-1750dhp2 Version-
BuffaloWxr18000be10p Firmware Version < 5.03
   BuffaloWxr18000be10p Version-
BuffaloWxr-1900dhp Firmware Version < 2.53
   BuffaloWxr-1900dhp Version-
BuffaloWxr-1900dhp2 Firmware Version < 2.62
   BuffaloWxr-1900dhp2 Version-
BuffaloWxr-1900dhp3 Firmware Version < 2.66
   BuffaloWxr-1900dhp3 Version-
BuffaloWxr-5950ax12 Firmware Version < 3.57
   BuffaloWxr-5950ax12 Version-
BuffaloWxr-6000ax12b Firmware Version < 3.57
   BuffaloWxr-6000ax12b Version-
BuffaloWxr-6000ax12p Firmware Version < 3.57
   BuffaloWxr-6000ax12p Version-
BuffaloWxr-6000ax12s Firmware Version < 3.57
   BuffaloWxr-6000ax12s Version-
BuffaloWzr-1166dhp Firmware Version < 2.20
   BuffaloWzr-1166dhp Version-
BuffaloWzr-1166dhp2 Firmware Version < 2.20
   BuffaloWzr-1166dhp2 Version-
BuffaloWzr-1750dhp Firmware Version < 2.32
   BuffaloWzr-1750dhp Version-
BuffaloWzr-1750dhp2 Firmware Version < 2.33
   BuffaloWzr-1750dhp2 Version-
BuffaloWzr-s1750dhp Firmware Version < 2.34
   BuffaloWzr-s1750dhp Version-
BuffaloWrm-d2133hp Firmware Version < 3.01
   BuffaloWrm-d2133hp Version-
BuffaloWrm-d2133hs Firmware Version < 3.01
   BuffaloWrm-d2133hs Version-
BuffaloWtr-m2133hp Firmware Version < 3.01
   BuffaloWtr-m2133hp Version-
BuffaloWtr-m2133hs Firmware Version < 3.01
   BuffaloWtr-m2133hs Version-
BuffaloWem-1266 Firmware Version < 2.87
   BuffaloWem-1266 Version-
BuffaloWem-1266wp Firmware Version < 2.87
   BuffaloWem-1266wp Version-
BuffaloVr-u300w Firmware Version < 1.42
   BuffaloVr-u300w Version-
BuffaloVr-u500x Firmware Version < 1.42
   BuffaloVr-u500x Version-
BuffaloWapm-1266r Firmware Version < 1.42
   BuffaloWapm-1266r Version-
BuffaloWapm-1266wdpr Firmware Version < 1.42
   BuffaloWapm-1266wdpr Version-
BuffaloWapm-1266wdpra Firmware Version < 1.42
   BuffaloWapm-1266wdpra Version-
BuffaloWapm-1750d Firmware Version < 1.07
   BuffaloWapm-1750d Version-
BuffaloWapm-2133r Firmware Version < 1.42
   BuffaloWapm-2133r Version-
BuffaloWapm-2133tr Firmware Version < 1.42
   BuffaloWapm-2133tr Version-
BuffaloWapm-ax4r Firmware Version < 1.42
   BuffaloWapm-ax4r Version-
BuffaloWapm-ax8r Firmware Version < 1.42
   BuffaloWapm-ax8r Version-
BuffaloWapm-axetr Firmware Version < 1.42
   BuffaloWapm-axetr Version-
BuffaloWaps-1266 Firmware Version < 1.42
   BuffaloWaps-1266 Version-
BuffaloWaps-ax4 Firmware Version < 1.42
   BuffaloWaps-ax4 Version-
BuffaloFs-m1266 Firmware Version < 4.13
   BuffaloFs-m1266 Version-
BuffaloFs-s1266 Firmware Version < 4.13
   BuffaloFs-s1266 Version-
BuffaloWzr-600dhp Firmware Version-
   BuffaloWzr-600dhp Version-
BuffaloWzr-600dhp2 Firmware Version-
   BuffaloWzr-600dhp2 Version-
BuffaloWzr-600dhp3 Firmware Version-
   BuffaloWzr-600dhp3 Version-
BuffaloWzr-900dhp Firmware Version-
   BuffaloWzr-900dhp Version-
BuffaloWzr-900dhp2 Firmware Version-
   BuffaloWzr-900dhp2 Version-
BuffaloWzr-s600dhp Firmware Version-
   BuffaloWzr-s600dhp Version-
BuffaloWzr-s900dhp Firmware Version-
   BuffaloWzr-s900dhp Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.09% 0.26
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vultures@jpcert.or.jp 8.6 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vultures@jpcert.or.jp 7.2 1.2 5.9
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-912 Hidden Functionality

The product contains functionality that is not documented, not part of the specification, and not accessible through an interface or command sequence that is obvious to the product's users or administrators.