Description
BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command.
Published: 2026-09-28
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Remote code execution
Action: Assess Impact
AI Analysis

Impact

Buffalo Wi‑Fi appliances containing the WEX‑G300 and WSR‑300HP models mishandle certain web form fields. When an administrative user submits a specially crafted HTTP request, the device concatenates the input into an internal command string and executes it as a shell command. This flaw allows the attacker to run arbitrary operating‑system commands on the affected device, potentially leading to full system compromise, data theft, or availability disruption.

Affected Systems

The vulnerability affects Buffalo's WEX‑G300 and WSR‑300HP Wi‑Fi products. These are hardware routers and access points that run embedded firmware with a web‑based administration interface.

Risk and Exploitability

The CVSS score of 8.6 indicates a high severity exposure. The EPSS score is not available, so the precise exploitation probability is uncertain, but the lack of a CISA KEV listing suggests it is not a known, actively exploited vulnerability at this time. Attackers who gain administrative access to the web interface or can convince an administrative user to trigger a malformed request have a viable exploitation path. No specific conditions beyond authentication to the web console are required, making the threat surface relatively broad for affected units.

Generated by OpenCVE AI on September 28, 2026 at 09:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update device firmware to the latest version provided by Buffalo that addresses the command‑execution flaw
  • If no update is available, restrict administrative web interface access to a trusted internal network or apply firewall rules to block external HTTP connections
  • Monitor device logs for anomalous command execution attempts and investigate any unauthorized activity promptly

Generated by OpenCVE AI on September 28, 2026 at 09:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Title Administrative Privilege Exploit Enables OS Command Execution via Web Form Input

Mon, 28 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Description BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-28T08:14:00.049Z

Reserved: 2026-09-24T08:54:17.872Z

Link: CVE-2026-86530

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T09:17:07.653

Modified: 2026-09-28T09:17:07.653

Link: CVE-2026-86530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T09:30:14Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')