CVE-2023-46681: Buffalo Vr-s1000 Firmware

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in VR-S1000 firmware Ver. 2.37 and earlier allows an authenticated attacker who can access to the product's command line interface to execute an arbitrary command.

Affected products

  • Buffalo Vr-s1000 Firmware: up to and including 2.37

Published 2023-12-26. Last modified 2026-06-17.