Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 20 Oct 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Buffalo
Buffalo navigator2 Microsoft Microsoft windows |
|
| Vendors & Products |
Buffalo
Buffalo navigator2 Microsoft Microsoft windows |
Fri, 10 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 10 Oct 2025 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NAS Navigator2 Windows version by BUFFALO INC. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege. | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2025-10-10T18:32:49.428Z
Reserved: 2025-10-02T23:47:37.697Z
Link: CVE-2025-61871
Updated: 2025-10-10T18:32:45.789Z
Status : Deferred
Published: 2025-10-10T05:15:33.587
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-61871
No data.
OpenCVE Enrichment
Updated: 2025-10-20T16:25:31Z