CVE-2025-61941 Details
Description
A path traversal issue exists in WXR9300BE6P series firmware versions prior to Ver.1.10. Arbitrary file may be altered by an administrative user who logs in to the affected product. Moreover, arbitrary OS command may be executed via some file alteration.
A path traversal vulnerability has been identified in the Buffalo WXR9300BE6P series Wi-Fi router, specifically in firmware versions prior to 1.10. This vulnerability allows an administrative user to alter arbitrary files on the device. Additionally, certain file modifications could be exploited to execute arbitrary operating system commands.
Users are advised to update the router's firmware to version 1.10 or later. The latest firmware versions can be downloaded from the Buffalo support website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 15, 2025CISA-ADP
Assessed Oct 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/vu/JVNVU96471278/ | [email protected] | AdvisoryRemedy |
| https://www.buffalo.jp/news/detail/20251014-01.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Buffalo WXR9300BE6P | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 15, 2025 | New CVE Received | [email protected] |
Volerion