Only two models are affected — the WSR-300HP Wi-Fi router and the WEX-G300 Wi-Fi extender — and the fixed firmware shipped before the disclosure.
On 28 September 2026 JPCERT/CC published JVNVU#94863997, covering two vulnerabilities in the configuration screens of Buffalo Wi-Fi products. Buffalo published its own advisory the same day.
Buffalo states plainly that if the automatic firmware update feature is enabled, the update has already been applied and no action is required. Automatic update is enabled by default on both models.
So if the installed version already reads as the fixed one, this is a check and nothing more. The test is the installed firmware version, not whether you remember switching automatic updates off. If the unit is not on Ver. 2.55 or later (WSR-300HP) or Ver. 1.71 or later (WEX-G300), it needs attention whatever the reason. As covered below, there is firmware old enough to predate the automatic update feature entirely.
Affected models and the fixed firmware
Taken from JVN. Anything older than the versions below is affected.
- ▸WSR-300HP (Wi-Fi router) — firmware older than Ver. 2.55. The fixed Ver. 2.55 was released on 25 August 2026
- ▸WEX-G300 (Wi-Fi extender) — firmware older than Ver. 1.71. The fixed Ver. 1.71 was released on 3 September 2026
Neither JVN nor Buffalo lists any other model. This is not a blanket "Buffalo routers are unsafe" story, so start by reading the model number off the label on the unit.
These are Japan-market products, so the vendor pages are Japanese only. The flaws were reported to JPCERT/CC, which coordinated the fix with Buffalo.
The two flaws do different things
Treating them as one lump labelled "critical" leads to the wrong decision, so here they are separately. These are the impacts JVN lists.
- ▸CVE-2026-86530 (OS command injection / CWE-78) — an authenticated user can have crafted input processed and execute arbitrary OS commands. CVSS v4.0 8.6, CVSS v3.1 7.2
- ▸CVE-2026-95104 (stack-based buffer overflow / CWE-121) — crafted input causes a denial of service. This one needs no authentication (the vector reads PR:N), scoring CVSS v4.0 8.7 and CVSS v3.1 7.5
The higher number belongs to the unauthenticated denial of service (8.7), but all it achieves is disruption. The one that reaches arbitrary OS command execution requires authentication first: JVN describes it as carried out by an authenticated user, and the CVSS vector reads PR:H, meaning high privileges. Neither source names an administrator account specifically, but both point at a privileged login.
Both enter through the configuration screen, so what matters is who can reach that screen. The next section is where that changes.
Exposing the configuration screen to the internet changes the picture
Buffalo adds one sentence after describing the impacts: if the setting that permits remote access from the internet side is enabled, attacks can be carried out from the internet.
That setting is the only condition Buffalo singles out. If you have made the configuration screen reachable from outside the house, the set of people who can attempt these attacks widens to anyone on the internet. If you are not using remote administration, turn it off.
The fixed firmware does not mention a security fix in its change log
This is worth knowing, because reading the change log will not tell you that these releases fix a vulnerability. Here is what Buffalo’s download pages actually list.
WSR-300HP Ver. 2.55 (25 August 2026) — two fixes: other devices failing to obtain an IP address when the unit is used as an access point, and false positives in other devices’ loop detection. That is all.
WEX-G300 Ver. 1.71 (3 September 2026) — one fix: other devices failing to obtain an IP address when the unit is connected to the network. That is all.
So "the change log only lists bug fixes, this can wait" is not a valid reading. Judge by the version number alone.
Automatic update was added partway through, and old firmware does not have it
Buffalo says automatic update is enabled by default, but there is firmware old enough to predate the feature entirely. The change logs date its arrival.
The WSR-300HP gained the automatic firmware update feature in Ver. 2.30 (25 May 2016). For the WEX-G300 it was Ver. 1.30 (16 June 2016).
A unit still running firmware older than that has no mechanism to pull a new version on its own. Not having the feature and not having it switched on are different states, but they produce the same outcome: no update arrives. So "I never turned automatic updates off" does not settle it. Those units have to be updated by hand.
What to do today
- ✓Read the model number off the label. Anything other than WSR-300HP or WEX-G300 is out of scope here
- ✓Open the configuration screen and check the firmware version under Management, then Firmware Update
- ✓Confirm you are on Ver. 2.55 or later (WSR-300HP) or Ver. 1.71 or later (WEX-G300). If you are, you are done
- ✓If not, look on the same screen for an automatic firmware update option at all. If it is there and switched off, switch it on. If the option does not exist, the firmware predates the feature — update by hand from the download pages below
- ✓If remote access from the internet side is enabled and you do not use it, turn it off
- ✓Check that the administrator password is not still the factory default. CVE-2026-86530 assumes an authenticated user, so a guessable password satisfies that assumption for the attacker
The unit loses its internet connection during the update, and on a metered connection the download adds to your data usage. Do it when you have time. Both points come from Buffalo’s own notes on the automatic update feature.
Searching for the CVEs returns nothing yet (as of 28 September 2026)
Neither CVE ID has a page on NVD yet. Here is what the checks returned.
Querying the CVE ID service run by CVE.org shows both CVE-2026-86530 and CVE-2026-95104 in the RESERVED state; the record endpoint returns 404 and the NVD API returns zero results. Requesting the NVD detail page returns a 301 to the same detail path with the identifier lowercased. That URL then serves the NVD home-page content, and the identifier appears nowhere on it.
That does not mean the identifiers are fake. They are assigned, and the details are in the JVN and Buffalo advisories. Today those two pages are the primary sources. There is no telling when the records will appear on NVD, but their absence is not a reason to treat this as unconfirmed.
Three lines to pass on
- ▸Buffalo WSR-300HP (router) and WEX-G300 (extender) have flaws in their configuration screens. No other model is listed
- ▸The fixes are Ver. 2.55 and Ver. 1.71. Automatic update is on by default, so if the version already reads as the fixed one, reading it is all that is needed
- ▸Act today if the version is below the fixed release. Never having disabled automatic updates does not help if the firmware predates the feature. The change log does not mention the security fix, so go by the version number alone
Sources
- JVNVU#94863997: Multiple vulnerabilities in Buffalo Wi-Fi products (affected versions, CVSS, impacts, fixed firmware dates)↗
- Buffalo advisory: multiple vulnerabilities in some Wi-Fi products and how to address them (JVNVU#94863997)↗
- Buffalo download: WSR-300HP firmware (Windows) Ver. 2.55 — change log and when automatic update was added↗
- Buffalo download: WSR-300HP firmware (Mac) Ver. 2.55↗
- Buffalo download: WEX-G300 firmware (Windows) Ver. 1.71 — change log and when automatic update was added↗
- Buffalo download: WEX-G300 firmware (Mac) Ver. 1.71↗
