CVE-2026-86530

Summary

BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command.

Affected Software

VendorProductVersion RangeStatus
BUFFALO INC.WSR-300HP0 < Ver.2.55affected
BUFFALO INC.WEX-G3000 < Ver.1.71affected

Weaknesses

  • CWE-78: Improper neutralization of special elements used in an OS command ('OS Command Injection')

References