CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2025-61871: NAS Navigator2 (Windows version only) prior to Ver.3.12.0

CVE-2025-61871. EPSS 0.00168 (percentile 0.05517), scored 2026-10-06.

Affected technology

NAS Navigator2 (Windows version only) · prior to Ver.3.12.0
BUFFALO INC.

Description’s affected range: version by BUFFALO INC. registers a Windows service with an unquoted file path

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Local · High privileges required · No user interaction required

What an attacker can do

The source reports that an attacker could run attacker-chosen code. Vendor/CNA’s CVSS 4.0 assessment (base score 8.4/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-428
CCR priority
0.0 /100 (P5)
EPSS
0.00168 · percentile 0.05549 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-61871.html