CRITICAL
CVE-2021-20090
CVSS
9.8
KEV
Description
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.
Summary dbcve.org
A path traversal vulnerability in Buffalo WSR-2533DHPL2 (firmware <= 1.02) and WSR-2533DHP3 (firmware <= 1.24) web interfaces allows unauthenticated remote attackers to bypass authentication via directory traversal sequences in HTTP requests.
Mitigation
Apply vendor-supplied firmware updates to remediate the path traversal vulnerability. If no update is available, restrict web interface access to trusted networks or disable remote management.
Weakness (CWE)
CWE-22
Path Traversal
EPSS Score
99.98%
Probability of exploitation in next 30 days
100th percentile
References
https://www.kb.cert.org/vuls/id/914124
Third Party Advisory, US Government Resource
https://www.secpod.com/blog/arcadyan-based-routers-and-modems-under-active-exploitation/
Exploit, Third Party Advisory
https://www.tenable.com/security/research/tra-2021-13
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20090
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.