A vulnerability, which was classified as critical , has been found in Buffalo Wi-Fi Router . This affects an unknown function. Performing a manipulation results in missing authentication. This vulnerability was named CVE-2026-33366 . The attack may be initiated remotely. There is no available exploit.
Full text archived locally
✦ AI Summary· Claude Sonnet
VDB-353824 · CVE-2026-33366 · GCVE-0-2026-33366
BUFFALO WI-FI ROUTER MISSING AUTHENTICATION
HISTORYDIFFRELATEJSONXMLCTI
CVSS Meta Temp Score Current Exploit Price (≈) CTI Interest Score
5.3 $0-$5k 3.21+
Summaryinfo
A vulnerability, which was classified as critical, was found in Buffalo Wi-Fi Router. This impacts an unknown function. Executing a manipulation can lead to missing authentication. The identification of this vulnerability is CVE-2026-33366. The attack may be launched remotely. There is no exploit available.
Detailsinfo
A vulnerability was found in Buffalo Wi-Fi Router (affected version not known). It has been declared as critical. This vulnerability affects some unknown functionality. The manipulation with an unknown input leads to a missing authentication vulnerability. The CWE definition for the vulnerability is CWE-306. The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. As an impact it is known to affect availability. CVE summarizes:
Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to forcibly reboot the product without authentication.
The advisory is shared for download at buffalo.jp. This vulnerability was named CVE-2026-33366 since 03/25/2026. The exploitation appears to be easy. The attack can be initiated remotely. No form of authentication is required for a successful exploitation. There are neither technical details nor an exploit publicly available. The current price for an exploit might be approx. USD $0-$5k (estimation calculated on 03/27/2026).
There is no information about possible countermeasures known. It may be suggested to replace the affected object with an alternative product.
Productinfo
Type
Router Operating System
Vendor
Buffalo
Name
Wi-Fi Router
License
commercial
CPE 2.3info
🔒
CPE 2.2info
🔒
CVSSv4info
VulDB Vector: 🔒
VulDB Reliability: 🔍
CNA CVSS-B Score: 🔒
CNA CVSS-BT Score: 🔒
CNA Vector: 🔒
CVSSv3info
VulDB Meta Base Score: 5.3
VulDB Meta Temp Score: 5.3
VulDB Base Score: 5.3
VulDB Temp Score: 5.3
VulDB Vector: 🔒
VulDB Reliability: 🔍
CNA Base Score: 5.3
CNA Vector (jpcert): 🔒
CVSSv2info
Vector Complexity Authentication Confidentiality Integrity Availability
Unlock Unlock Unlock Unlock Unlock Unlock
Unlock Unlock Unlock Unlock Unlock Unlock
Unlock Unlock Unlock Unlock Unlock Unlock
VulDB Base Score: 🔒
VulDB Temp Score: 🔒
VulDB Reliability: 🔍
Exploitinginfo
Class: Missing authentication
CWE: CWE-306 / CWE-287
CAPEC: 🔒
ATT&CK: 🔒
Physical: No
Local: No
Remote: Yes
Availability: 🔒
Status: Not defined
Price Prediction: 🔍
Current Price Estimation: 🔒
0-Day Unlock Unlock Unlock Unlock
Today Unlock Unlock Unlock Unlock
Threat Intelligenceinfo
Interest: 🔍
Active Actors: 🔍
Active APT Groups: 🔍
Countermeasuresinfo
Recommended: no mitigation known
Status: 🔍
0-Day Time: 🔒
Timelineinfo
03/25/2026 CVE reserved
03/27/2026 +2 days Advisory disclosed
03/27/2026 +0 days VulDB entry created
03/27/2026 +0 days VulDB entry last update
Sourcesinfo
Advisory: buffalo.jp
Status: Confirmed
CVE: CVE-2026-33366 (🔒)
GCVE (CVE): GCVE-0-2026-33366
GCVE (VulDB): GCVE-100-353824
Entryinfo
Created: 03/27/2026 07:31
Changes: 03/27/2026 07:31 (73)
Complete: 🔍
Cache ID: 99:6F3:101
Discussion
No comments yet. Languages: en.
Please log in to comment.
◂ PreviousOverviewNext ▸