Buffalo records
61 published records for vendor buffalo.
Researcher profile
- Entered KEV
- 1 · 1.6%
- Weaponized
- 1 · 1.6%
- Pre-auth RCE
- 11
- With a fix record
- 0%
- Median publish → KEV
- 188 days
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')13
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor3
- CWE-306 Missing Authentication for Critical Function3
- CWE-287 Improper Authentication3
The weakness classes this vendor ships most often: where to look.
CWEAll records
61 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2021-20090Weaponized | A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= buffalo · wsr-2533dhpl2-bk firmware · CWE-22 | Critical9.8 | KEV | 100.0% | Apr 29, 2021 |
46Plan | CVE-2018-13324No exploit | Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified buffalo · ts5600d1206 firmware · CWE-863 | Critical9.8 | — | 23.2% | Nov 26, 2018 |
40Plan | CVE-2017-2126No exploit | WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication andbuffalo · wapm-1166d firmware · CWE-287 | Critical9.8 | — | 4.0% | Jul 21, 2017 |
40Plan | CVE-2021-20716No exploit | Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 buffalo · bhr-4rv firmware | Critical9.8 | — | 3.2% | Apr 27, 2021 |
39Monitor | CVE-2018-16988No exploit | An issue was discovered in Open XDMoD through 7.5.0.buffalo · open xdmod · CWE-640 | Critical9.8 | — | 1.6% | May 2, 2019 |
39Monitor | CVE-2024-23486No exploit | Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wibuffalo · wsr-2533dhp firmware · CWE-256 | Critical9.8 | — | 0.6% | Apr 15, 2024 |
38Monitor | CVE-2021-20091Proof of concept | The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize userbuffalo · wsr-2533dhpl2-bk firmware | High8.8 | — | 8.8% | Apr 29, 2021 |
37Monitor | CVE-2026-45779No exploit | Open XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Database Compromisebuffalo · open xdmod · CWE-89 | Critical9.3 | — | 0.9% | Jun 5, 2026 |
37Monitor | CVE-2026-45777No exploit | Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command Injectionbuffalo · open xdmod · CWE-78 | Critical9.3 | — | 0.7% | Jun 5, 2026 |
35Monitor | CVE-2018-13321No exploit | Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal functions via the "mbuffalo · ts5600d1206 firmware · CWE-732 | High8.8 | — | 1.0% | Nov 26, 2018 |
35Monitor | CVE-2021-3512No exploit | Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 anbuffalo · bhr-4grv firmware | High8.8 | — | 0.9% | Apr 27, 2021 |
35Monitor | CVE-2018-0554No exploit | Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspebuffalo · wzr-1750dhp2 firmware · CWE-306 | High8.8 | — | 0.8% | Apr 9, 2018 |
35Monitor | CVE-2018-0521No exploit | Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device buffalo · wxr-1900dhp2 firmware · CWE-306 | High8.8 | — | 0.8% | Mar 9, 2018 |
35Monitor | CVE-2022-43443No exploit | OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a spbuffalo · wsr-3200ax4s firmware · CWE-78 | High8.8 | — | 0.8% | Dec 18, 2022 |
35Monitor | CVE-2017-2273No exploit | Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remobuffalo · wmr-433 firmware · CWE-352 | High8.8 | — | 0.8% | Jul 21, 2017 |
35Monitor | CVE-2018-0556No exploit | Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.buffalo · wzr-1750dhp2 firmware · CWE-78 | High8.8 | — | 0.7% | Apr 9, 2018 |
35Monitor | CVE-2018-0523No exploit | Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.buffalo · wxr-1900dhp2 firmware · CWE-78 | High8.8 | — | 0.7% | Mar 9, 2018 |
35Monitor | CVE-2021-20731No exploit | WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands witbuffalo · wsr-1166dhp4 firmware · CWE-78 | High8.8 | — | 0.6% | Jun 8, 2021 |
35Monitor | CVE-2022-40966No exploit | Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and accebuffalo · wcr-300 firmware · CWE-287 | High8.8 | — | 0.4% | Dec 7, 2022 |
34Monitor | CVE-2026-27650No exploit | OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products.buffalo · wcr-1166dhpl firmware · CWE-78 | High8.6 | — | 1.4% | Mar 27, 2026 |
34Monitor | CVE-2026-33280No exploit | Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging fubuffalo · wcr-1166dhpl firmware · CWE-912 | High8.6 | — | 0.7% | Mar 27, 2026 |
34Monitor | CVE-2026-32678No exploit | Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings wibuffalo · wzr-s900dhp firmware · CWE-288 | High8.7 | — | 0.5% | Mar 27, 2026 |
34Monitor | CVE-2026-32669No exploit | Code injection vulnerability exists in BUFFALO Wi-Fi router products.buffalo · wcr-1166dhpl firmware · CWE-94 | High8.7 | — | 0.5% | Mar 27, 2026 |
34Monitor | CVE-2026-45778No exploit | Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Resetbuffalo · open xdmod · CWE-79 | High8.6 | — | 0.2% | Jun 5, 2026 |
32Monitor | CVE-2021-20092Proof of concept | The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict accebuffalo · wsr-2533dhpl2-bk firmware · CWE-287 | High7.5 | — | 8.2% | Apr 29, 2021 |
- CVE-2021-2009099Now
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <=
CriticalCVSS 9.8KEVWeaponizedEPSS 100%buffalo · wsr-2533dhpl2-bk firmwareApr 29, 2021
- CVE-2018-1332446Plan
Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified
CriticalCVSS 9.8No exploitEPSS 23%buffalo · ts5600d1206 firmwareNov 26, 2018
- CVE-2017-212640Plan
WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and
CriticalCVSS 9.8No exploitEPSS 4%buffalo · wapm-1166d firmwareJul 21, 2017
- CVE-2021-2071640Plan
Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11
CriticalCVSS 9.8No exploitEPSS 3%buffalo · bhr-4rv firmwareApr 27, 2021
- CVE-2018-1698839Monitor
An issue was discovered in Open XDMoD through 7.5.0.
CriticalCVSS 9.8No exploitEPSS 2%buffalo · open xdmodMay 2, 2019
- CVE-2024-2348639Monitor
Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker wi
CriticalCVSS 9.8No exploitEPSS 1%buffalo · wsr-2533dhp firmwareApr 15, 2024
- CVE-2021-2009138Monitor
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user
HighCVSS 8.8Proof of conceptEPSS 9%buffalo · wsr-2533dhpl2-bk firmwareApr 29, 2021
- CVE-2026-4577937Monitor
Open XDMoD Vulnerable to Unauthenticated SQL Injection Leading to Full Database Compromise
CriticalCVSS 9.3No exploitEPSS 1%buffalo · open xdmodJun 5, 2026
- CVE-2026-4577737Monitor
Open XDMoD Vulnerable to Unauthenticated Remote Code Execution (RCE) via OS Command Injection
CriticalCVSS 9.3No exploitEPSS 1%buffalo · open xdmodJun 5, 2026
- CVE-2018-1332135Monitor
Incorrect access controls in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allow attackers to call dangerous internal functions via the "m
HighCVSS 8.8No exploitEPSS 1%buffalo · ts5600d1206 firmwareNov 26, 2018
- CVE-2021-351235Monitor
Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 an
HighCVSS 8.8No exploitEPSS 1%buffalo · bhr-4grv firmwareApr 27, 2021
- CVE-2018-055435Monitor
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspe
HighCVSS 8.8No exploitEPSS 1%buffalo · wzr-1750dhp2 firmwareApr 9, 2018
- CVE-2018-052135Monitor
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device
HighCVSS 8.8No exploitEPSS 1%buffalo · wxr-1900dhp2 firmwareMar 9, 2018
- CVE-2022-4344335Monitor
OS command injection vulnerability in Buffalo network devices allows an network-adjacent attacker to execute an arbitrary OS command if a sp
HighCVSS 8.8No exploitEPSS 1%buffalo · wsr-3200ax4s firmwareDec 18, 2022
- CVE-2017-227335Monitor
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remo
HighCVSS 8.8No exploitEPSS 1%buffalo · wmr-433 firmwareJul 21, 2017
- CVE-2018-055635Monitor
Buffalo WZR-1750DHP2 Ver.2.30 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
HighCVSS 8.8No exploitEPSS 1%buffalo · wzr-1750dhp2 firmwareApr 9, 2018
- CVE-2018-052335Monitor
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
HighCVSS 8.8No exploitEPSS 1%buffalo · wxr-1900dhp2 firmwareMar 9, 2018
- CVE-2021-2073135Monitor
WSR-1166DHP3 firmware Ver.1.16 and prior and WSR-1166DHP4 firmware Ver.1.02 and prior allow an attacker to execute arbitrary OS commands wit
HighCVSS 8.8No exploitEPSS 1%buffalo · wsr-1166dhp4 firmwareJun 8, 2021
- CVE-2022-4096635Monitor
Authentication bypass vulnerability in multiple Buffalo network devices allows a network-adjacent attacker to bypass authentication and acce
HighCVSS 8.8No exploitEPSS 0%buffalo · wcr-300 firmwareDec 7, 2022
- CVE-2026-2765034Monitor
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products.
HighCVSS 8.6No exploitEPSS 1%buffalo · wcr-1166dhpl firmwareMar 27, 2026
- CVE-2026-3328034Monitor
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging fu
HighCVSS 8.6No exploitEPSS 1%buffalo · wcr-1166dhpl firmwareMar 27, 2026
- CVE-2026-3267834Monitor
Authentication bypass issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to alter critical configuration settings wi
HighCVSS 8.7No exploitEPSS 1%buffalo · wzr-s900dhp firmwareMar 27, 2026
- CVE-2026-3266934Monitor
Code injection vulnerability exists in BUFFALO Wi-Fi router products.
HighCVSS 8.7No exploitEPSS 0%buffalo · wcr-1166dhpl firmwareMar 27, 2026
- CVE-2026-4577834Monitor
Open XDMoD Vulnerable to Reflected Cross-Site Scripting (XSS) in Password Reset
HighCVSS 8.6No exploitEPSS 0%buffalo · open xdmodJun 5, 2026
- CVE-2021-2009232Monitor
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict acce
HighCVSS 7.5Proof of conceptEPSS 8%buffalo · wsr-2533dhpl2-bk firmwareApr 29, 2021