CVE-2021-20091 is a critical vulnerability affecting the web interfaces of Buffalo WSR-2533DHPL2 (firmware <= 1.02) and WSR-2533DHP3 (firmware <= 1.24) routers due to improper user input sanitization. This allows an authenticated remote attacker to alter device configuration, potentially leading to remote code execution. With a CVSS score of 8.8 (HIGH) and an EPSS score indicating high exploitability, the vulnerability presents a significant risk. Although not listed in CISA's KEV catalog, exploit intelligence shows available Nuclei templates for configuration file injection. Community discussion and media coverage suggest awareness and potential for exploitation, as evidenced by a SecurityWeek article detailing exploitation of similar vulnerabilities shortly after disclosure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.02CPE matchmatch criteria | cpe:2.3:o:buffalo:wsr-2533dhpl2-bk_firmware:*:*:*:*:*:*:*:* | ||
<= 1.24CPE matchmatch criteria | cpe:2.3:o:buffalo:wsr-2533dhp3-bk_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021Multiple Vulnerabilities in Buffalo and Arcadyan manufactured routers
Apr 23, 2021