CVE-2021-20090 is a critical path traversal vulnerability affecting Buffalo WSR-2533DHPL2 (firmware <= 1.02) and WSR-2533DHP3 (firmware <= 1.24) routers, allowing unauthenticated remote attackers to bypass authentication. With a CVSS score of 9.8, this vulnerability is easily exploitable over the network without user interaction, leading to complete compromise of confidentiality, integrity, and availability. It is actively exploited in the wild, as evidenced by its inclusion in CISA's KEV catalog and numerous media reports detailing its use in botnet campaigns. While no Metasploit or ExploitDB modules exist, Nuclei templates are available, and there is significant community discussion and media coverage surrounding this high-risk flaw.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.02CPE matchmatch criteria | cpe:2.3:o:buffalo:wsr-2533dhpl2-bk_firmware:*:*:*:*:*:*:*:* | ||
<= 1.24CPE matchmatch criteria | cpe:2.3:o:buffalo:wsr-2533dhp3-bk_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021