Published:2026/09/28  Last Updated:2026/09/28

JVNVU#94863997
Multiple vulnerabilities in BUFFALO Wi-Fi Products

Overview

Wi-Fi products provided by BUFFALO INC. contain multiple vulnerabilities.

Products Affected

  • WSR-300HP firmware versions prior to Ver.2.55
  • WEX-G300 firmware versions prior to Ver.1.71

Description

The web configuration user interfaces of Wi-Fi products provided by BUFFALO INC. contain multiple vulnerabilities listed below.

  • OS command injection (CWE-78)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.6
    • CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Base Score 7.2
    • CVE-2026-86530
  • Stack-based buffer overflow (CWE-121)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Base Score 8.7
    • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Base Score 7.5
    • CVE-2026-95104

Impact

  • An administrative user may send a crafted HTTP request and execute an arbitrary OS command (CVE-2026-86530).
  • A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition (CVE-2026-95104).

Solution

Update the firmware
Update the firmware to the latest version according to the information provided by the developer.

The fixed versions are provided on the following date:

  • WSR-300HP firmware Ver.2.55, August 25, 2026
  • WEX-G300 firmware Ver.1.71, September 3, 2026
The affected products may be automatically updated if "automatic firmware update" feature is enabled.

Vendor Status

Vendor Status Last Update Vendor Notes
BUFFALO INC. Vulnerable 2026/09/28 BUFFALO INC. website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Veeti Punnonen reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-86530
CVE-2026-95104
JVN iPedia