Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Buffalo

First CVE: Jun 19, 2016Active for: 10 yearsTotal CVEs: 62
50.1
VTI Score
TOP TARGET

Buffalo manufactures a portfolio of consumer and small-business wireless networking devices, including routers and storage appliances across its WZR product line, many deployed in environments with extended service lifecycles. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, and recur across product lines through weakness classes including OS command injection, cross-site scripting, and path traversal—issues endemic to embedded firmware and web-management interfaces. These embedded-device vulnerability patterns reflect the complexity of authenticating and validating input on firmware-based management surfaces that often remain internet-reachable. Defenders should inventory Buffalo devices in their environments and prioritize firmware updates where available, especially for internet-facing administrative access; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
62
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
1.6%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Buffalo over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 19, 2016
10 years ago
Most Recent CVE
Jun 5, 2026
49 days ago

Products(361 total)

Top CVEs

Signals from CVEs in this vendor scope (62 CVEs).

62 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-20090CRITICAL
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote
Apr 29, 20219.898YESYES
CVE-2021-20091HIGH
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input. An authenticated remote attacker
Apr 29, 20218.843NOYES
CVE-2018-13324CRITICAL
Incorrect access control in nasapi in Buffalo TS5600D1206 version 3.61-0.10 allows attackers to bypass authentication by sending a modified HTTP Host header.
Nov 26, 20189.843NONO
CVE-2026-45779CRITICAL
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated
Jun 5, 20269.840NONO
CVE-2026-45777CRITICAL
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system co
Jun 5, 20269.839NONO
CVE-2021-20092HIGH
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unau
Apr 29, 20217.538NOYES
CVE-2026-27650CRITICAL
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.
Mar 27, 20269.834NONO
CVE-2026-32669CRITICAL
Code injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary code may be executed on the products.
Mar 27, 20269.833NONO
CVE-2026-33280CRITICAL
Hidden functionality issue exists in BUFFALO Wi-Fi router products, which may allow an attacker to gain access to the product’s debugging functionality, resulting in the execution
Mar 27, 20269.831NONO
CVE-2021-20716CRITICAL
Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 fi
Apr 28, 20219.831NONO
View all 62 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products62 CVEs
40%
42%
18%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (6.5%)
Network37 (59.7%)
Unknown0 (0.0%)
Physical1 (1.6%)
Adjacent Network20 (32.3%)
Attack Complexity
Low61 (98.4%)
High1 (1.6%)
Unknown0 (0.0%)
User Interaction
None51 (82.3%)
Unknown0 (0.0%)
Required11 (17.7%)
Privileges Required
Low8 (12.9%)
High11 (17.7%)
None43 (69.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (62 CVEs).

CISA KEV
1 CVE
1.6% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
4.8% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Buffalo.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Buffalo — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Buffalo's Products

View all 4 CNAs →

Top CWEs