First published: Thu Apr 29 2021(Updated: )
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input. An authenticated remote attacker could leverage this vulnerability to alter device configuration, potentially gaining remote code execution.
Credit: vulnreport@tenable.com
Affected Software | Affected Version | How to fix |
---|---|---|
Arcadyan Buffalo Firmware | <=1.02 | |
Buffalo Wsr-2533dhpl2 | ||
Buffalo Wsr-2533dhp3-bk Firmware | <=1.24 | |
Buffalo WSR-2533DHP3-BK |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20091 is a vulnerability in Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 that allows an authenticated remote attacker to alter device configuration and potentially gain remote code execution.
CVE-2021-20091 affects Buffalo WSR-2533DHPL2 firmware version <= 1.02 by not properly sanitizing user input, which can be exploited by an authenticated remote attacker to alter device configuration and potentially achieve remote code execution.
CVE-2021-20091 impacts Buffalo WSR-2533DHP3 firmware version <= 1.24 by not properly sanitizing user input, allowing an authenticated remote attacker to manipulate device configuration and potentially execute code remotely.
CVE-2021-20091 has a severity rating of 8.8 (high).
To mitigate CVE-2021-20091, update Buffalo WSR-2533DHPL2 firmware to version 1.03 or later, and update Buffalo WSR-2533DHP3 firmware to version 1.25 or later.