ZeroHour

CVE-2021-20090

KEV PoC ×2mass1

Unauthenticated Path Traversal in Arcadyan Buffalo Router Firmware

CISA: Arcadyan Buffalo Firmware Path Traversal Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2021-20090 is a path traversal flaw (CWE-22) in the web interface of Arcadyan's Buffalo router firmware. By sending crafted HTTP requests containing directory traversal sequences, an unauthenticated, remote attacker can bypass the device's authentication. Successful exploitation grants access to sensitive information and otherwise protected functionality on the router without valid credentials. The flaw affects multiple router models across several different vendors, because Arcadyan's Buffalo firmware is embedded in a range of OEM and ISP-distributed products. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV catalog on 2021-11-03, and EPSS rates the probability of exploitation within 30 days at 100% (100th percentile).

What to do: Apply firmware updates from the router vendor as directed in the CISA KEV required action. Until patched, restrict or disable WAN-side remote management of the device's web interface. Review router configurations for unauthorized changes after patching, since unauthenticated remote access was possible.

Affected
Arcadyan Buffalo Firmware
Estimated exposure
massplausibly millions of deployed consumer/ISP routers; internet-exposed subset unknown — Arcadyan's Buffalo firmware is OEM-embedded in routers distributed by several large carriers, so affected device populations plausibly run into the millions, though no public scan count of internet-exposed units is available in this data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.

CISA Known Exploited Vulnerability
Affected
Arcadyan Buffalo Firmware
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
buffalo
Products
wsr-2533dhpl2-bk firmware, wsr-2533dhp3-bk firmware
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news