CVE-2026-33366: Medium severity Buffalo BUFFALO Wi-Fi routers vulnerability

Published Mar 27, 2026
·
Updated

Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product without authentication.

Affected Software

93 affected components
Buffalo BUFFALO Wi-Fi routers
All of the following
Buffalo Wcr-1166dhpl Firmware<1.01
Buffalo Wcr-1166dhpl
All of the following
Buffalo Wsr3600be4-kh Firmware<6.02
Buffalo Wsr3600be4-kh
All of the following
Buffalo Wsr3600be4p Firmware<5.02
Buffalo Wsr3600be4p
All of the following
Buffalo WXR-1750DHP firmware<2.63
Buffalo WXR-1750DHP
All of the following
Buffalo WXR-1750DHP2 firmware<2.63
Buffalo WXR-1750DHP2
All of the following
Buffalo Wxr18000be10p Firmware<5.03
Buffalo Wxr18000be10p
All of the following
Buffalo WXR-1900DHP firmware<2.53
Buffalo WXR-1900DHP
All of the following
Buffalo WXR-1900DHP2 firmware<2.62
Buffalo WXR-1900DHP2
All of the following
Buffalo WXR-1900DHP3 firmware<2.66
Buffalo WXR-1900DHP3
All of the following
Buffalo WXR-5950AX12 firmware<3.57
Buffalo WXR-5950AX12
All of the following
Buffalo WXR-6000AX12B firmware<3.57
Buffalo WXR-6000AX12B
All of the following
Buffalo Wxr-6000ax12p Firmware<3.57
Buffalo Wxr-6000ax12p
All of the following
Buffalo WXR-6000AX12S firmware<3.57
Buffalo WXR-6000AX12S
All of the following
Buffalo WZR-1166DHP firmware<2.20
Buffalo WZR-1166DHP
All of the following
Buffalo WZR-1166DHP2 firmware<2.20
Buffalo WZR-1166DHP2
All of the following
Buffalo WZR-1750DHP firmware<2.32
Buffalo WZR-1750DHP
All of the following
Buffalo WZR-1750DHP2 firmware<2.33
Buffalo WZR-1750DHP2
All of the following
Buffalo WZR-S1750DHP firmware<2.34
Buffalo WZR-S1750DHP
All of the following
Buffalo WRM-D2133HP firmware<3.01
Buffalo WRM-D2133HP
All of the following
Buffalo WRM-D2133HS firmware<3.01
Buffalo WRM-D2133HS
All of the following
Buffalo WTR-M2133HP firmware<3.01
Buffalo WTR-M2133HP
All of the following
Buffalo WTR-M2133HS firmware<3.01
Buffalo WTR-M2133HS
All of the following
Buffalo WEM-1266 firmware<2.87
Buffalo WEM-1266
All of the following
Buffalo WEM-1266WP firmware<2.87
Buffalo WEM-1266WP
All of the following
Buffalo Vr-u300w Firmware<1.42
Buffalo Vr-u300w
All of the following
Buffalo Vr-u500x Firmware<1.42
Buffalo Vr-u500x
All of the following
Buffalo Wapm-1266r Firmware<1.42
Buffalo Wapm-1266r
All of the following
Buffalo Wapm-1266wdpr Firmware<1.42
Buffalo Wapm-1266wdpr
All of the following
Buffalo Wapm-1266wdpra Firmware<1.42
Buffalo Wapm-1266wdpra
All of the following
Buffalo Wapm-1750d Firmware<1.07
Buffalo Wapm-1750d
All of the following
Buffalo Wapm-2133r Firmware<1.42
Buffalo Wapm-2133r
All of the following
Buffalo Wapm-2133tr Firmware<1.42
Buffalo Wapm-2133tr
All of the following
Buffalo Wapm-ax4r Firmware<1.42
Buffalo Wapm-ax4r
All of the following
Buffalo Wapm-ax8r Firmware<1.42
Buffalo Wapm-ax8r
All of the following
Buffalo Wapm-axetr Firmware<1.42
Buffalo Wapm-axetr
All of the following
Buffalo Waps-1266 Firmware<1.42
Buffalo Waps-1266
All of the following
Buffalo Waps-ax4 Firmware<1.42
Buffalo Waps-ax4
All of the following
Buffalo Fs-m1266 Firmware<4.13
Buffalo Fs-m1266
All of the following
Buffalo Fs-s1266 Firmware<4.13
Buffalo Fs-s1266
All of the following
Buffalo WZR-600DHP firmware
Buffalo WZR-600DHP
All of the following
Buffalo WZR-600DHP2 firmware
Buffalo WZR-600DHP2
All of the following
Buffalo WZR-600DHP3 firmware
Buffalo WZR-600DHP3
All of the following
Buffalo WZR-900DHP firmware
Buffalo WZR-900DHP
All of the following
Buffalo WZR-900DHP2 firmware
Buffalo WZR-900DHP2
All of the following
Buffalo WZR-S600DHP firmware
Buffalo WZR-S600DHP
All of the following
Buffalo WZR-S900DHP firmware
Buffalo WZR-S900DHP

Event History

Mar 27, 2026
CVE Published
via MITRE·05:25 AM
Data Sourced
via MITRE·05:25 AM
DescriptionSeverity
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-33366?

CVE-2026-33366 is classified as a critical severity vulnerability due to the potential for unauthorized system access.

2

How do I fix CVE-2026-33366?

To fix CVE-2026-33366, update your BUFFALO Wi-Fi router to the latest firmware version provided by the manufacturer.

3

What are the consequences of CVE-2026-33366?

The consequences of CVE-2026-33366 include the ability for attackers to forcibly reboot the router, leading to service disruption.

4

Is my device affected by CVE-2026-33366?

If you are using BUFFALO Wi-Fi routers, your device is potentially affected by CVE-2026-33366.

5

What should I do if I cannot update my BUFFALO Wi-Fi router for CVE-2026-33366?

If an update is not possible, consider disconnecting the device from the network until a fix is applied.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203