CRITICAL · 9.8

CVE-2026-33280

Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS comm...

Vulnerability Description

Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS commands.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BuffaloWcr-1166Dhpl Firmware< 1.01
BuffaloWcr-1166Dhpl-
BuffaloWsr3600Be4-Kh Firmware< 6.02
BuffaloWsr3600Be4-Kh-
BuffaloWsr3600Be4P Firmware< 5.02
BuffaloWsr3600Be4P-
BuffaloWxr-1750Dhp Firmware< 2.63
BuffaloWxr-1750Dhp-
BuffaloWxr-1750Dhp2 Firmware< 2.63
BuffaloWxr-1750Dhp2-
BuffaloWxr18000Be10P Firmware< 5.03
BuffaloWxr18000Be10P-
BuffaloWxr-1900Dhp Firmware< 2.53
BuffaloWxr-1900Dhp-
BuffaloWxr-1900Dhp2 Firmware< 2.62
BuffaloWxr-1900Dhp2-
BuffaloWxr-1900Dhp3 Firmware< 2.66
BuffaloWxr-1900Dhp3-
BuffaloWxr-5950Ax12 Firmware< 3.57
BuffaloWxr-5950Ax12-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-33280?

CVE-2026-33280 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution of arbitrary OS comm...

How severe is CVE-2026-33280?

CVE-2026-33280 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2026-33280?

Check the references section above for vendor advisories and patch information. Affected products include: Buffalo Wcr-1166Dhpl Firmware, Buffalo Wcr-1166Dhpl, Buffalo Wsr3600Be4-Kh Firmware, Buffalo Wsr3600Be4-Kh, Buffalo Wsr3600Be4P Firmware.