Sceawere

Vulnerability Detail

CVE-2026-86530UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

BUFFALO Wi-Fi OS Command Injection

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
3h ago
Vendor
BUFFALO INC.
Product
WSR-300HP
Attack Type
Improper neutralization of special elements used in an OS command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

BUFFALO Wi-Fi products handle some web form input improperly to assemble command line strings internally. An administrative user may send a crafted HTTP request and execute an arbitrary OS command.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-09-28T09:17:07.653Z",
  "pubdate": "2026-09-28T09:17:07.653Z",
  "executiveSummary": "This vulnerability is an OS Command Injection flaw identified in various BUFFALO Wi-Fi products. The vulnerability exists due to the insecure handling of web form inputs when constructing internal command-line strings.\nSuccessful exploitation allows an authenticated administrative user to execute arbitrary operating system commands with elevated privileges on the underlying host.\nThe vulnerability poses a critical risk to the integrity, confidentiality, and availability of the affected devices. By bypassing intended input sanitization mechanisms, an attacker can gain full control over the appliance, potentially leading to unauthorized access to sensitive network data, persistent malware installation, or complete device compromise.\nExploitation requires administrative access to the web-based management interface. Attackers must be able to craft malicious HTTP requests that manipulate internal process execution through improper input handling within the administrative control forms.\nThe inherent risk is high, as the vulnerability enables lateral movement within the network or the interception of traffic traversing the Wi-Fi gateway.",
  "technicalDetails": "The root cause of this vulnerability is improper input validation and sanitization within the web administrative interface of BUFFALO Wi-Fi products. When the web application processes administrative input, it fails to sufficiently neutralize shell metacharacters before incorporating user-supplied data into command-line execution functions.\nTechnically, the vulnerability manifests when the application backend invokes system calls (such as system(), popen(), or exec()) to perform administrative tasks, such as configuring network settings or diagnostics. Because the application constructs these shell commands via string concatenation without strict filtering or parameterization, an attacker can supply crafted input containing shell operators—such as semicolons (;), pipes (|), or backticks (`)—to terminate the intended command and inject arbitrary payloads.\nThe attack flow proceeds as follows: First, the attacker authenticates as an administrative user on the device's web management interface. Second, the attacker identifies a specific form field intended for configuration or diagnostic parameters that is processed on the backend via a vulnerable function. Third, the attacker submits an HTTP POST or GET request where the input parameter contains the malicious shell syntax. Fourth, the server-side script fails to sanitize the input, passing the concatenated malicious string directly to the underlying shell environment for execution.\nBecause the web server process typically runs with root or superuser privileges on embedded Linux-based firmware, the injected commands are executed with these high-level permissions. This allows the attacker to execute binary files, modify configuration files, exfiltrate private keys, or disable security features entirely.\nThe exploit bypasses traditional interface restrictions by manipulating the logic flow of the backend interpreter, effectively turning administrative management forms into an interactive command shell. Once the command is executed, the attacker may establish persistent access through a reverse shell or by modifying the startup scripts of the firmware, resulting in long-term device compromise. The vulnerability is characterized by a failure to employ secure coding practices, such as using white-list validation for inputs or utilizing API methods that avoid shell-based execution entirely."
}
CVE-2026-86530: BUFFALO Wi-Fi OS Command Injection (HIGH Severity, CVSS: 7.2) | Sceawere