CVE-2025-61941

7.2

Buffalo Inc. · WXR9300BE6P series

A path traversal vulnerability in Buffalo WXR9300BE6P firmware allows an authenticated administrator to modify arbitrary files and potentially execute OS commands.

Executive summary

An authenticated path traversal vulnerability in Buffalo WXR9300BE6P series firmware permits arbitrary file manipulation and command execution, posing a critical risk to device integrity.

Vulnerability

This vulnerability is a path traversal flaw (CWE-22) that allows an administrative user to escape restricted directories. By manipulating file paths, an attacker with administrative credentials can modify system files, which may subsequently lead to arbitrary OS command execution.

Business impact

The ability to perform arbitrary file modifications and execute OS commands grants an attacker complete control over the affected networking hardware. With a CVSS score of 7.2, this vulnerability is considered high severity as it enables unauthorized system changes, potential data exfiltration, or the establishment of persistent backdoors within the network infrastructure.

Remediation

Immediate Action: Update the firmware of all affected WXR9300BE6P devices to version 1.10 or later as specified by the vendor advisory.

Proactive Monitoring: Review administrative access logs for unusual file modification patterns or attempts to access system-level directories that fall outside of expected management operations.

Compensating Controls: Restrict administrative access to the device management interface to trusted internal IP addresses only, ensuring that only authorized personnel can reach the vulnerable endpoint.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Security teams must prioritize the deployment of the vendor-provided firmware update to version 1.10. Given that this vulnerability allows for administrative-level system compromise, patching is the only effective way to remediate the underlying path traversal risk and prevent unauthorized OS command execution.

More Buffalo Inc. CVEs

Sources