CVE-2025-61871: Buffalo Inc NAS NAVIGATOR2 Windows Version Only

High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.

NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.

Affected products

  • Buffalo Inc NAS NAVIGATOR2 Windows Version Only: before 3.12.0 (fixed in 3.12.0)

Published 2025-10-10. Last modified 2026-10-08.