CVE-2026-27650: Command Injection
Published Mar 27, 2026
·Updated
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.
Affected Software
93 affected components
Buffalo BUFFALO Wi-Fi router
All of the following
Buffalo Wcr-1166dhpl Firmware<1.01
Buffalo Wcr-1166dhpl
All of the following
Buffalo Wsr3600be4-kh Firmware<6.02
Buffalo Wsr3600be4-kh
All of the following
Buffalo Wsr3600be4p Firmware<5.02
Buffalo Wsr3600be4p
All of the following
Buffalo WXR-1750DHP firmware<2.63
Buffalo WXR-1750DHP
All of the following
Buffalo WXR-1750DHP2 firmware<2.63
Buffalo WXR-1750DHP2
All of the following
Buffalo Wxr18000be10p Firmware<5.03
Buffalo Wxr18000be10p
All of the following
Buffalo WXR-1900DHP firmware<2.53
Buffalo WXR-1900DHP
All of the following
Buffalo WXR-1900DHP2 firmware<2.62
Buffalo WXR-1900DHP2
All of the following
Buffalo WXR-1900DHP3 firmware<2.66
Buffalo WXR-1900DHP3
All of the following
Buffalo WXR-5950AX12 firmware<3.57
Buffalo WXR-5950AX12
All of the following
Buffalo WXR-6000AX12B firmware<3.57
Buffalo WXR-6000AX12B
All of the following
Buffalo Wxr-6000ax12p Firmware<3.57
Buffalo Wxr-6000ax12p
All of the following
Buffalo WXR-6000AX12S firmware<3.57
Buffalo WXR-6000AX12S
All of the following
Buffalo WZR-1166DHP firmware<2.20
Buffalo WZR-1166DHP
All of the following
Buffalo WZR-1166DHP2 firmware<2.20
Buffalo WZR-1166DHP2
All of the following
Buffalo WZR-1750DHP firmware<2.32
Buffalo WZR-1750DHP
All of the following
Buffalo WZR-1750DHP2 firmware<2.33
Buffalo WZR-1750DHP2
All of the following
Buffalo WZR-S1750DHP firmware<2.34
Buffalo WZR-S1750DHP
All of the following
Buffalo WRM-D2133HP firmware<3.01
Buffalo WRM-D2133HP
All of the following
Buffalo WRM-D2133HS firmware<3.01
Buffalo WRM-D2133HS
All of the following
Buffalo WTR-M2133HP firmware<3.01
Buffalo WTR-M2133HP
All of the following
Buffalo WTR-M2133HS firmware<3.01
Buffalo WTR-M2133HS
All of the following
Buffalo WEM-1266 firmware<2.87
Buffalo WEM-1266
All of the following
Buffalo WEM-1266WP firmware<2.87
Buffalo WEM-1266WP
All of the following
Buffalo Vr-u300w Firmware<1.42
Buffalo Vr-u300w
All of the following
Buffalo Vr-u500x Firmware<1.42
Buffalo Vr-u500x
All of the following
Buffalo Wapm-1266r Firmware<1.42
Buffalo Wapm-1266r
All of the following
Buffalo Wapm-1266wdpr Firmware<1.42
Buffalo Wapm-1266wdpr
All of the following
Buffalo Wapm-1266wdpra Firmware<1.42
Buffalo Wapm-1266wdpra
All of the following
Buffalo Wapm-1750d Firmware<1.07
Buffalo Wapm-1750d
All of the following
Buffalo Wapm-2133r Firmware<1.42
Buffalo Wapm-2133r
All of the following
Buffalo Wapm-2133tr Firmware<1.42
Buffalo Wapm-2133tr
All of the following
Buffalo Wapm-ax4r Firmware<1.42
Buffalo Wapm-ax4r
All of the following
Buffalo Wapm-ax8r Firmware<1.42
Buffalo Wapm-ax8r
All of the following
Buffalo Wapm-axetr Firmware<1.42
Buffalo Wapm-axetr
All of the following
Buffalo Waps-1266 Firmware<1.42
Buffalo Waps-1266
All of the following
Buffalo Waps-ax4 Firmware<1.42
Buffalo Waps-ax4
All of the following
Buffalo Fs-m1266 Firmware<4.13
Buffalo Fs-m1266
All of the following
Buffalo Fs-s1266 Firmware<4.13
Buffalo Fs-s1266
All of the following
Buffalo WZR-600DHP firmware
Buffalo WZR-600DHP
All of the following
Buffalo WZR-600DHP2 firmware
Buffalo WZR-600DHP2
All of the following
Buffalo WZR-600DHP3 firmware
Buffalo WZR-600DHP3
All of the following
Buffalo WZR-900DHP firmware
Buffalo WZR-900DHP
All of the following
Buffalo WZR-900DHP2 firmware
Buffalo WZR-900DHP2
All of the following
Buffalo WZR-S600DHP firmware
Buffalo WZR-S600DHP
All of the following
Buffalo WZR-S900DHP firmware
Buffalo WZR-S900DHP
Event History
Mar 27, 2026
CVE Published
via MITRE·05:24 AM
Data Sourced
via MITRE·05:24 AM
DescriptionSeverity
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-27650?
CVE-2026-27650 is classified as a high severity vulnerability due to the potential for remote command execution.
2
How do I fix CVE-2026-27650?
To fix CVE-2026-27650, update the firmware of your BUFFALO Wi-Fi router to the latest version provided by the manufacturer.
3
What products are affected by CVE-2026-27650?
CVE-2026-27650 affects various BUFFALO Wi-Fi router products.
4
What type of attack does CVE-2026-27650 enable?
CVE-2026-27650 enables an OS command injection attack, allowing arbitrary commands to be executed on the router.
5
Is CVE-2026-27650 being exploited in the wild?
At this time, there is no public information confirming active exploitation of CVE-2026-27650 in the wild.