Two high-severity vulnerabilities have been disclosed in BUFFALO Wi-Fi router products, exposing affected devices to arbitrary code execution and OS command execution. CVE-2026-32669 is classified as CWE-94 and allows code injection that could let an attacker run arbitrary code on vulnerable routers, while CVE-2026-33280 is a CWE-912 hidden functionality flaw that could expose debugging features and enable arbitrary OS commands.
Both issues carry high impact across confidentiality, integrity, and availability, with published scoring indicating network-based exploitation and low attack complexity for the command injection issue. The vulnerability records list JPCERT/CC as the receiving party, and references were added to JVN and a BUFFALO advisory page, signaling vendor and coordination activity around the affected router line.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A new vulnerability record for CVE-2026-27650 was received on March 27, 2026, describing an OS command injection flaw in BUFFALO Wi-Fi router products that could allow arbitrary OS command execution. The entry references JVN and a BUFFALO advisory and maps the issue to CWE-78 with high severity impact.
A new vulnerability record for CVE-2026-33280 was recorded on March 27, 2026, affecting BUFFALO Wi-Fi router products. The flaw is described as hidden functionality that could expose debugging features and enable arbitrary OS command execution, with high impact across confidentiality, integrity, and availability.
A new vulnerability record for CVE-2026-32669 was received on March 27, 2026, describing a code injection flaw in BUFFALO Wi-Fi router products that could allow arbitrary code execution. The entry references JVN and a BUFFALO advisory and classifies the issue as CWE-94 with high confidentiality, integrity, and availability impact.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.