CVE-2021-20716: Critical severity arcadyan buffalo firmware vulnerability
Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 firmware Ver.2.32 and prior, WBR2-G54-KD firmware Ver.2.32 and prior, WBR-B11 firmware Ver.2.23 and prior, WBR-G54 firmware Ver.2.23 and prior, WBR-G54L firmware Ver.2.20 and prior, WHR2-A54G54 firmware Ver.2.25 and prior, WHR2-G54 firmware Ver.2.23 and prior, WHR2-G54V firmware Ver.2.55 and prior, WHR3-AG54 firmware Ver.2.23 and prior, WHR-G54 firmware Ver.2.16 and prior, WHR-G54-NF firmware Ver.2.10 and prior, WLA2-G54 firmware Ver.2.24 and prior, WLA2-G54C firmware Ver.2.24 and prior, WLA-B11 firmware Ver.2.20 and prior, WLA-G54 firmware Ver.2.20 and prior, WLA-G54C firmware Ver.2.20 and prior, WLAH-A54G54 firmware Ver.2.54 and prior, WLAH-AM54G54 firmware Ver.2.54 and prior, WLAH-G54 firmware Ver.2.54 and prior, WLI2-TX1-AG54 firmware Ver.2.53 and prior, WLI2-TX1-AMG54 firmware Ver.2.53 and prior, WLI2-TX1-G54 firmware Ver.2.20 and prior, WLI3-TX1-AMG54 firmware Ver.2.53 and prior, WLI3-TX1-G54 firmware Ver.2.53 and prior, WLI-T1-B11 firmware Ver.2.20 and prior, WLI-TX1-G54 firmware Ver.2.20 and prior, WVR-G54-NF firmware Ver.2.02 and prior, WZR-G108 firmware Ver.2.41 and prior, WZR-G54 firmware Ver.2.41 and prior, WZR-HP-G54 firmware Ver.2.41 and prior, WZR-RS-G54 firmware Ver.2.55 and prior, and WZR-RS-G54HP firmware Ver.2.55 and prior) allows a remote attacker to enable the debug option and to execute arbitrary code or OS commands, change the configuration, and cause a denial of service (DoS) condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20716?
CVE-2021-20716 is classified as a high severity vulnerability due to its potential for allowing unauthorized access to device functionality.
How do I fix CVE-2021-20716?
To mitigate CVE-2021-20716, update the affected Buffalo network device firmware to the latest version beyond the vulnerable releases.
Which devices are affected by CVE-2021-20716?
CVE-2021-20716 affects various Buffalo network devices, including BHR-4RV, FS-G54, WBR2-B11, WBR2-G54, and others with specific firmware versions.
What potential risks are associated with CVE-2021-20716?
Exploitation of CVE-2021-20716 could allow attackers to access hidden functionalities, which may lead to unauthorized control or data breaches.
Is there a workaround for CVE-2021-20716 if I can't update immediately?
Disabling remote access and restricting network access to the device can serve as a temporary workaround for CVE-2021-20716 until a firmware update can be applied.