PT-2021-3736 · Buffalo · Buffalo Wsr-2533Dhp3+1

Evan Grant

·

Published

2020-09-30

·

Updated

2025-12-03

·

CVE-2021-20090

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Buffalo WSR-2533DHPL2 firmware version <= 1.02 Buffalo WSR-2533DHP3 firmware version <= 1.24
Description A path traversal vulnerability in the web interfaces of Buffalo routers could allow unauthenticated remote attackers to bypass authentication. This issue is related to the possibility of directory path traversal, which may enable a remote attacker to circumvent the authentication process.
Recommendations For Buffalo WSR-2533DHPL2 firmware version <= 1.02, consider disabling remote access to the web interface until a patch is available. For Buffalo WSR-2533DHP3 firmware version <= 1.24, restrict access to the vulnerable web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Code Injection

Path traversal

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03989
BDU:2021-04036
BDU:2021-04037
BDU:2021-04215
CVE-2021-20090

Affected Products

Buffalo Wsr-2533Dhp3
Buffalo Wsr-2533Dhpl2