Record summary

CVE-2021-20091 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.

Description

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input. An authenticated remote attacker could leverage this vulnerability to alter device configuration, potentially gaining remote code execution.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Sep 20, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3

CVE ListWSR-2533DHPL2 <=1.02, WSR-2533DHP3 <= 1.24affected

Nuclei templates

1
ProjectDiscoveryHIGHBuffalo WSR-2533DHPL2 - Configuration File InjectionCVSS 8.8

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 does not properly sanitize user input. An authenticated remote attacker could leverage this vulnerability to alter device configuration, potentially leading to remote code execution.

Impact

An attacker can exploit this vulnerability to inject malicious configuration settings, potentially leading to unauthorized access or control of the router.

Remediation

Apply the latest firmware update provided by Buffalo to fix the configuration file injection vulnerability.

Authorsgy741, pdteam, parth
Template tagscve2021cvebuffalofirmwareiottenablevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:h:buffalo:wsr-2533dhpl2-bk:-:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2