CVE-2025-61871: High severity Buffalo NAS Navigator2 vulnerability

Published Oct 10, 2025
·
Updated

NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

Affected Software

1 affected component
Buffalo NAS Navigator2

Event History

Oct 10, 2025
CVE Published
via MITRE·04:52 AM
Data Sourced
via MITRE·04:52 AM
DescriptionSeverity
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-61871?

CVE-2025-61871 has a high severity due to potential arbitrary code execution with SYSTEM privileges.

2

What causes CVE-2025-61871?

CVE-2025-61871 is caused by the unquoted file path of a Windows service registered by NAS Navigator2.

3

How do I fix CVE-2025-61871?

To fix CVE-2025-61871, ensure that the service path is properly quoted to prevent arbitrary command execution.

4

Who is affected by CVE-2025-61871?

CVE-2025-61871 affects users of Buffalo NAS Navigator2 on Windows systems.

5

What can attackers potentially do with CVE-2025-61871?

Attackers can exploit CVE-2025-61871 to execute arbitrary code with SYSTEM privileges if they have write access to the root directory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203