PT-2021-14175 · Buffalo · Whr2-G54+25

Chuya Hayakawa

·

Published

2021-04-28

·

Updated

2021-05-07

·

CVE-2021-20716

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: BHR-4RV firmware Ver.2.55 and prior FS-G54 firmware Ver.2.04 and prior WBR2-B11 firmware Ver.2.32 and prior WBR2-G54 firmware Ver.2.32 and prior WBR2-G54-KD firmware Ver.2.32 and prior WBR-B11 firmware Ver.2.23 and prior WBR-G54 firmware Ver.2.23 and prior WBR-G54L firmware Ver.2.20 and prior WHR2-A54G54 firmware Ver.2.25 and prior WHR2-G54 firmware Ver.2.23 and prior WHR2-G54V firmware Ver.2.55 and prior WHR3-AG54 firmware Ver.2.23 and prior WHR-G54 firmware Ver.2.16 and prior WHR-G54-NF firmware Ver.2.10 and prior WLA2-G54 firmware Ver.2.24 and prior WLA2-G54C firmware Ver.2.24 and prior WLA-B11 firmware Ver.2.20 and prior WLA-G54 firmware Ver.2.20 and prior WLA-G54C firmware Ver.2.20 and prior WLAH-A54G54 firmware Ver.2.54 and prior WLAH-AM54G54 firmware Ver.2.54 and prior WLAH-G54 firmware Ver.2.54 and prior WLI2-TX1-AG54 firmware Ver.2.53 and prior WLI2-TX1-AMG54 firmware Ver.2.53 and prior WLI2-TX1-G54 firmware Ver.2.20 and prior WLI3-TX1-AMG54 firmware Ver.2.53 and prior WLI3-TX1-G54 firmware Ver.2.53 and prior WLI-T1-B11 firmware Ver.2.20 and prior WLI-TX1-G54 firmware Ver.2.20 and prior WVR-G54-NF firmware Ver.2.02 and prior WZR-G108 firmware Ver.2.41 and prior WZR-G54 firmware Ver.2.41 and prior WZR-HP-G54 firmware Ver.2.41 and prior WZR-RS-G54 firmware Ver.2.55 and prior WZR-RS-G54HP firmware Ver.2.55 and prior
Description: Hidden functionality in multiple Buffalo network devices allows a remote attacker to enable the debug option and to execute arbitrary code or OS commands, change the configuration, and cause a denial of service (DoS) condition.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-20716

Affected Products

Bhr-4Grv
Fs-G54
Wbr-B11
Wbr-G54
Wbr2-B11
Wbr2-G54
Wbr2-G54-Kd
Whr-G54S
Whr-G54-Nf
Whr2-A54G54
Whr2-G54
Whr3-Ag54
Wla-B11
Wla-G54
Wla2-G54
Wlah-A54G54
Wli-T1-B11
Wli-Tx1-G54
Wli2-Tx1-Ag54
Wli3-Tx1-Amg54
Wvr-G54-Nf
Wzr-G108
Wzr-G54
Wzr-Hp-G54
Wzr-Rs-G54
Wzr-Rs-G54Hp