CVE-2025-26167: Infoleak
Published Mar 6, 2025
·Updated
Buffalo LS520D 4.53 is vulnerable to Arbitrary file read, which allows unauthenticated attackers to access the NAS web UI and read arbitrary internal files.
Affected Software
1 affected component
Buffalo LS520D
Event History
Mar 6, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-26167?
CVE-2025-26167 is classified as a critical vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2025-26167?
To fix CVE-2025-26167, users should update to the latest firmware provided by Buffalo for the LS520D.
3
What type of attack does CVE-2025-26167 enable?
CVE-2025-26167 enables arbitrary file read attacks, allowing unauthorized access to internal files.
4
Who is affected by CVE-2025-26167?
CVE-2025-26167 affects users of the Buffalo LS520D NAS device.
5
Can CVE-2025-26167 be exploited remotely?
Yes, CVE-2025-26167 can be exploited by unauthenticated attackers remotely through the NAS web UI.