Skip to finding
important · Wi-Fi

Buffalo's authenticated web command injection also reaches the WEX-G300 extender.

Affects

Buffalo WEX-G300, a consumer Wi-Fi range extender running embedded firmware.

An attacker with administrator credentials and configuration-interface access can escape a web-form field into an operating-system command.

Detail and 1 source
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 29, 2026