PT-2021-3736 · Buffalo · Buffalo Wsr-2533Dhp3+1
Evan Grant
·
Published
2020-09-30
·
Updated
2025-12-03
·
CVE-2021-20090
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Buffalo WSR-2533DHPL2 firmware version <= 1.02
Buffalo WSR-2533DHP3 firmware version <= 1.24
Description
A path traversal vulnerability in the web interfaces of Buffalo routers could allow unauthenticated remote attackers to bypass authentication. This issue is related to the possibility of directory path traversal, which may enable a remote attacker to circumvent the authentication process.
Recommendations
For Buffalo WSR-2533DHPL2 firmware version <= 1.02, consider disabling remote access to the web interface until a patch is available.
For Buffalo WSR-2533DHP3 firmware version <= 1.24, restrict access to the vulnerable web interface to minimize the risk of exploitation.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Code Injection
Path traversal
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Buffalo Wsr-2533Dhp3
Buffalo Wsr-2533Dhpl2