CVE-2021-20090
Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3
Published 29 Apr 2021 · updated 17 Jun 2026 · Analyzed
9.8 Critical · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 17 Nov 2021 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.
References
- www.kb.cert.org/vuls/id/914124 · Third Party Advisory, US Government Resource
- www.secpod.com/blog/arcadyan-based-routers-and-modems-under-active-exploitation/ · Exploit, Third Party Advisory
- www.tenable.com/security/research/tra-2021-13 · Exploit, Third Party Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20090 · US Government Resource