CVE-2025-61871: High severity Buffalo NAS Navigator2 vulnerability
Published Oct 10, 2025
·Updated
NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
Affected Software
1 affected component
Buffalo NAS Navigator2
Event History
Oct 10, 2025
CVE Published
via MITRE·04:52 AM
Data Sourced
via MITRE·04:52 AM
DescriptionSeverity
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-61871?
CVE-2025-61871 has a high severity due to potential arbitrary code execution with SYSTEM privileges.
2
What causes CVE-2025-61871?
CVE-2025-61871 is caused by the unquoted file path of a Windows service registered by NAS Navigator2.
3
How do I fix CVE-2025-61871?
To fix CVE-2025-61871, ensure that the service path is properly quoted to prevent arbitrary command execution.
4
Who is affected by CVE-2025-61871?
CVE-2025-61871 affects users of Buffalo NAS Navigator2 on Windows systems.
5
What can attackers potentially do with CVE-2025-61871?
Attackers can exploit CVE-2025-61871 to execute arbitrary code with SYSTEM privileges if they have write access to the root directory.