CVE-2025-61871: Buffalo Inc NAS NAVIGATOR2 Windows Version Only
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
Affected products
- Buffalo Inc NAS NAVIGATOR2 Windows Version Only: before 3.12.0 (fixed in 3.12.0)
Published 2025-10-10. Last modified 2026-10-08.