CVE-2021-20092 describes an improper access control vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 (firmware <= 1.02) and WSR-2533DHP3 (firmware <= 1.24) routers, allowing unauthorized actors to access sensitive information. This high-severity vulnerability (CVSS 7.5) is easily exploitable over the network without authentication, leading to a complete compromise of confidentiality. While not listed in CISA KEV, Nuclei templates exist for detection, and it has garnered significant community discussion and media coverage, including an article from Infosecurity Magazine. There is no evidence of active exploitation or public Metasploit modules.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.02CPE matchmatch criteria | cpe:2.3:o:buffalo:wsr-2533dhpl2-bk_firmware:*:*:*:*:*:*:*:* | ||
<= 1.24CPE matchmatch criteria | cpe:2.3:o:buffalo:wsr-2533dhp3-bk_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021