Buffalo manufactures a portfolio of consumer and small-business wireless networking devices, including routers and storage appliances across its WZR product line, many deployed in environments with extended service lifecycles. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur across product lines through weakness classes including OS command injection, cross-site scripting, and path traversal—issues endemic to embedded firmware and web-management interfaces. These embedded-device vulnerability patterns reflect the complexity of authenticating and validating input on firmware-based management surfaces that often remain internet-reachable. Defenders should inventory Buffalo devices in their environments and prioritize firmware updates where available, especially for internet-facing administrative access; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Buffalo over time
Signals from CVEs in this vendor scope (62 CVEs).
62 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-20090CRITICAL A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote | Apr 29, 2021 | 9.8 | 98 | YES | YES |
CVE-2021-20091HIGH The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input. An authenticated remote attacker | Apr 29, 2021 | 8.8 | 43 | NO | YES |
CVE-2018-13324CRITICAL Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host header. | Nov 26, 2018 | 9.8 | 43 | NO | NO |
CVE-2026-45779CRITICAL OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated | Jun 5, 2026 | 9.8 | 40 | NO | NO |
CVE-2026-45777CRITICAL OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system co | Jun 5, 2026 | 9.8 | 39 | NO | NO |
CVE-2021-20092HIGH The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unau | Apr 29, 2021 | 7.5 | 38 | NO | YES |
CVE-2026-27650CRITICAL OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products. | Mar 27, 2026 | 9.8 | 34 | NO | NO |
CVE-2026-32669CRITICAL Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the products. | Mar 27, 2026 | 9.8 | 33 | NO | NO |
CVE-2026-33280CRITICAL Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution | Mar 27, 2026 | 9.8 | 31 | NO | NO |
CVE-2021-20716CRITICAL Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 fi | Apr 28, 2021 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (62 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Buffalo.
Media articles that mention a CVE ID that affects a product developed by Buffalo — matched by CVE ID, not by vendor name.