ID

VAR-202603-4861


CVE

CVE-2026-33366


DESCRIPTION

Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product without authentication.

Trust: 1.0

sources: NVD: CVE-2026-33366

AFFECTED PRODUCTS

vendor:buffalomodel:vr-u500xscope:ltversion:1.42

Trust: 1.0

vendor:buffalomodel:wapm-ax4rscope:ltversion:1.42

Trust: 1.0

vendor:buffalomodel:wxr-1900dhpscope:ltversion:2.53

Trust: 1.0

vendor:buffalomodel:wem-1266wpscope:ltversion:2.87

Trust: 1.0

vendor:buffalomodel:fs-s1266scope:ltversion:4.13

Trust: 1.0

vendor:buffalomodel:wzr-900dhp2scope:eqversion: -

Trust: 1.0

vendor:buffalomodel:wapm-1750dscope:ltversion:1.07

Trust: 1.0

vendor:buffalomodel:wxr-1750dhp2scope:ltversion:2.63

Trust: 1.0

vendor:buffalomodel:wzr-1750dhp2scope:ltversion:2.33

Trust: 1.0

vendor:buffalomodel:wxr-5950ax12scope:ltversion:3.57

Trust: 1.0

vendor:buffalomodel:wsr3600be4-khscope:ltversion:6.02

Trust: 1.0

vendor:buffalomodel:wem-1266scope:ltversion:2.87

Trust: 1.0

vendor:buffalomodel:vr-u300wscope:ltversion:1.42

Trust: 1.0

vendor:buffalomodel:wapm-2133trscope:ltversion:1.42

Trust: 1.0

vendor:buffalomodel:wapm-2133rscope:ltversion:1.42

Trust: 1.0

vendor:buffalomodel:wrm-d2133hpscope:ltversion:3.01

Trust: 1.0

vendor:buffalomodel:wapm-1266wdprscope:ltversion:1.42

Trust: 1.0

vendor:buffalomodel:wapm-1266wdprascope:ltversion:1.42

Trust: 1.0

vendor:buffalomodel:wxr18000be10pscope:ltversion:5.03

Trust: 1.0

vendor:buffalomodel:wapm-axetrscope:ltversion:1.42

Trust: 1.0

vendor:buffalomodel:wzr-600dhpscope:eqversion: -

Trust: 1.0

vendor:buffalomodel:wzr-600dhp3scope:eqversion: -

Trust: 1.0

vendor:buffalomodel:wsr3600be4pscope:ltversion:5.02

Trust: 1.0

vendor:buffalomodel:wxr-1900dhp3scope:ltversion:2.66

Trust: 1.0

vendor:buffalomodel:wxr-6000ax12bscope:ltversion:3.57

Trust: 1.0

vendor:buffalomodel:wcr-1166dhplscope:ltversion:1.01

Trust: 1.0

vendor:buffalomodel:wapm-1266rscope:ltversion:1.42

Trust: 1.0

vendor:buffalomodel:wxr-6000ax12pscope:ltversion:3.57

Trust: 1.0

vendor:buffalomodel:wzr-1166dhpscope:ltversion:2.20

Trust: 1.0

vendor:buffalomodel:wtr-m2133hpscope:ltversion:3.01

Trust: 1.0

vendor:buffalomodel:waps-1266scope:ltversion:1.42

Trust: 1.0

vendor:buffalomodel:wzr-1166dhp2scope:ltversion:2.20

Trust: 1.0

vendor:buffalomodel:wzr-1750dhpscope:ltversion:2.32

Trust: 1.0

vendor:buffalomodel:wzr-900dhpscope:eqversion: -

Trust: 1.0

vendor:buffalomodel:wxr-1750dhpscope:ltversion:2.63

Trust: 1.0

vendor:buffalomodel:wapm-ax8rscope:ltversion:1.42

Trust: 1.0

vendor:buffalomodel:wzr-s600dhpscope:eqversion: -

Trust: 1.0

vendor:buffalomodel:wzr-s1750dhpscope:ltversion:2.34

Trust: 1.0

vendor:buffalomodel:fs-m1266scope:ltversion:4.13

Trust: 1.0

vendor:buffalomodel:waps-ax4scope:ltversion:1.42

Trust: 1.0

vendor:buffalomodel:wxr-6000ax12sscope:ltversion:3.57

Trust: 1.0

vendor:buffalomodel:wrm-d2133hsscope:ltversion:3.01

Trust: 1.0

vendor:buffalomodel:wtr-m2133hsscope:ltversion:3.01

Trust: 1.0

vendor:buffalomodel:wxr-1900dhp2scope:ltversion:2.62

Trust: 1.0

vendor:buffalomodel:wzr-s900dhpscope:eqversion: -

Trust: 1.0

vendor:buffalomodel:wzr-600dhp2scope:eqversion: -

Trust: 1.0

sources: NVD: CVE-2026-33366

CVSS

SEVERITY

CVSSV2

CVSSV3

vultures@jpcert.or.jp: CVE-2026-33366
value: MEDIUM

Trust: 1.0

vultures@jpcert.or.jp: CVE-2026-33366
baseSeverity: MEDIUM
baseScore: 5.3
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: LOW
exploitabilityScore: 3.9
impactScore: 1.4
version: 3.0

Trust: 1.0

sources: NVD: CVE-2026-33366

PROBLEMTYPE DATA

problemtype:CWE-306

Trust: 1.0

sources: NVD: CVE-2026-33366

EXTERNAL IDS

db:JVNid:JVN83788689

Trust: 1.0

db:NVDid:CVE-2026-33366

Trust: 1.0

sources: NVD: CVE-2026-33366

REFERENCES

url:https://jvn.jp/en/jp/jvn83788689/

Trust: 1.0

url:https://www.buffalo.jp/news/detail/20260323-01.html

Trust: 1.0

sources: NVD: CVE-2026-33366

SOURCES

db:NVDid:CVE-2026-33366

LAST UPDATE DATE

2026-04-02T23:16:31.932000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2026-33366date:2026-03-31T19:03:18.543

SOURCES RELEASE DATE

db:NVDid:CVE-2026-33366date:2026-03-27T06:16:38.997