CRITICAL

CVE-2021-20090

Buffalo Wsr 2533dhpl2 Bk Firmware 2021-04-29 CVSS v3.1
CVSS
9.8
KEV

Description

A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.

Summary dbcve.org

A path traversal vulnerability in Buffalo WSR-2533DHPL2 (firmware <= 1.02) and WSR-2533DHP3 (firmware <= 1.24) web interfaces allows unauthenticated remote attackers to bypass authentication via directory traversal sequences in HTTP requests.

Mitigation

Apply vendor-supplied firmware updates to remediate the path traversal vulnerability. If no update is available, restrict web interface access to trusted networks or disable remote management.

Proof of Concept

Weakness (CWE)

CWE-22 Path Traversal

EPSS Score

99.98%
Probability of exploitation in next 30 days
100th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE