Impact
Buffalo Wi‑Fi appliances containing the WEX‑G300 and WSR‑300HP models mishandle certain web form fields. When an administrative user submits a specially crafted HTTP request, the device concatenates the input into an internal command string and executes it as a shell command. This flaw allows the attacker to run arbitrary operating‑system commands on the affected device, potentially leading to full system compromise, data theft, or availability disruption.
Affected Systems
The vulnerability affects Buffalo's WEX‑G300 and WSR‑300HP Wi‑Fi products. These are hardware routers and access points that run embedded firmware with a web‑based administration interface.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity exposure. The EPSS score is not available, so the precise exploitation probability is uncertain, but the lack of a CISA KEV listing suggests it is not a known, actively exploited vulnerability at this time. Attackers who gain administrative access to the web interface or can convince an administrative user to trigger a malformed request have a viable exploitation path. No specific conditions beyond authentication to the web console are required, making the threat surface relatively broad for affected units.
OpenCVE Enrichment