CVE-2021-3512 is an improper access control vulnerability affecting numerous Buffalo broadband router models, allowing remote, unauthenticated attackers to bypass access restrictions. This flaw enables the activation of telnet services and the execution of arbitrary operating system commands with root privileges. Rated 8.8 HIGH on the CVSS scale, it presents a significant risk due to its adjacent network attack vector, low attack complexity, and high potential for confidentiality, integrity, and availability compromise. There is currently no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.00CPE matchmatch criteria | cpe:2.3:o:buffalo:bhr-4grv_firmware:*:*:*:*:*:*:*:* | ||
< 1.84CPE matchmatch criteria | cpe:2.3:o:buffalo:dwr-hp-g300nh_firmware:*:*:*:*:*:*:*:* | ||
< 2.00CPE matchmatch criteria | cpe:2.3:o:buffalo:hw-450hp-zwe_firmware:*:*:*:*:*:*:*:* | ||
< 2.00CPE matchmatch criteria | cpe:2.3:o:buffalo:whr-300hp_firmware:*:*:*:*:*:*:*:* | ||
< 2.00CPE matchmatch criteria | cpe:2.3:o:buffalo:whr-300_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.