Sceawere

Vulnerability Detail

CVE-2026-95104UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

BUFFALO Stack-Based Buffer Overflow

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
3h ago
Vendor
BUFFALO INC.
Product
WSR-300HP
Attack Type
Stack-based buffer overflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Complexity
LOW

Narrative and Response

Description

Stack-based buffer overflow vulnerability exists in BUFFALO Wi-Fi products. A non-authenticated crafted HTTP request may cause a denial-of-service (DoS) condition.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-28T09:17:08.697Z",
  "pubdate": "2026-09-28T09:17:08.697Z",
  "executiveSummary": "This vulnerability is identified as a stack-based buffer overflow within BUFFALO Wi-Fi networking products.\nThe flaw stems from improper boundary validation when processing HTTP requests, allowing an unauthenticated remote attacker to trigger a memory corruption condition.\nSuccessful exploitation results in a denial-of-service (DoS) state, rendering the affected device unresponsive and disrupting network operations.\nThe vulnerability resides at the network perimeter, requiring no user interaction or prior authentication to initiate the exploit.\nThe risk implication is significant for critical infrastructure and home/office network stability, as the device becomes unreachable until a manual hard reset is performed.\nAttackers can leverage this vulnerability to effectively take the device offline by sending a specifically crafted, malicious HTTP request targeting the vulnerable service.",
  "technicalDetails": "The vulnerability is characterized as a classic stack-based buffer overflow occurring within the HTTP request handling mechanism of the BUFFALO Wi-Fi device firmware.\nThe root cause of the vulnerability lies in the improper handling of input data during the parsing of HTTP headers or request parameters within the device's web server component.\nWhen the web server receives an HTTP request, it fails to perform adequate length validation on the input buffer before copying the data into a fixed-size stack-allocated memory space.\nAn attacker can exploit this by crafting an HTTP request containing a payload that exceeds the expected size of the destination buffer, thereby overflowing the buffer and overwriting adjacent memory regions on the stack.\nThis overwriting process corrupts critical control flow data, specifically the function return address stored on the stack frame.\nWhen the processor finishes execution of the current function, it attempts to return to the overwritten address, leading to a segmentation fault or an illegal instruction exception, which manifests as a service crash or complete system instability.\nThe attack flow follows a predictable sequence: First, the attacker initiates a network connection to the target device's HTTP management interface. Second, the attacker transmits a maliciously crafted HTTP request with an oversized payload. Third, the internal buffer is overwhelmed, leading to the corruption of the stack pointer and instruction pointer. Fourth, the system's execution flow is diverted to an invalid memory location, triggering an immediate DoS condition.\nBecause the web server component is exposed via the network and operates without pre-authentication, the attack surface is exposed to any device with network visibility to the web management interface.\nPost-exploitation impact is limited to system downtime; however, if the overflow allows for precise instruction pointer control, there is a theoretical potential for arbitrary code execution depending on the existence of existing security mitigations like ASLR or stack canaries, though the primary observed impact is limited to denial-of-service."
}
CVE-2026-95104: BUFFALO Stack-Based Buffer Overflow (HIGH Severity, CVSS: 7.5) | Sceawere