CVE-2021-20090: Arcadyan Buffalo Firmware Path Traversal Vulnerability
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.
Other sources
Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-20090?
CVE-2021-20090 is a path traversal vulnerability in Arcadyan Buffalo firmware that allows unauthenticated, remote attackers to bypass authentication and access sensitive information.
Which routers are affected by CVE-2021-20090?
The vulnerability affects multiple routers across several different vendors using Arcadyan Buffalo firmware.
What is the severity of CVE-2021-20090?
The severity of CVE-2021-20090 is rated as critical with a CVSS score of 9.8.
How can I fix CVE-2021-20090?
To fix CVE-2021-20090, update the firmware of affected routers to a patched version provided by the vendor.
Where can I find more information about CVE-2021-20090?
More information about CVE-2021-20090 can be found at the following references: [1] [2] [3].