CVE-2024-23486: Buffalo Wsr-2533dhp2 Firmware

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Plaintext storage of a password issue exists in BUFFALO wireless LAN routers, which may allow a network-adjacent unauthenticated attacker with access to the product's login page may obtain configured credentials.

Affected products

  • Buffalo Wsr-2533dhp2 Firmware: before 1.11 (fixed in 1.11)
  • Buffalo Wsr-2533dhp Firmware: before 1.07 (fixed in 1.07)
  • Buffalo Wsr-2533dhpl Firmware: before 1.07 (fixed in 1.07)
  • Buffalo Wsr-a2533dhp2 Firmware: before 1.11 (fixed in 1.11)

Published 2024-04-15. Last modified 2026-06-17.