CVE-2021-20091
Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 Configuration Injection
Record summary
CVE-2021-20091 has a selected CVSS score of 8.8 (high); EIP currently links 1 Nuclei template.
Description
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input. An authenticated remote attacker could leverage this vulnerability to alter device configuration, potentially gaining remote code execution.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Sep 20, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
wsr-2533dhpl2-bk_firmwareBrowse buffalo / wsr-2533dhpl2-bk_firmware | VulnCheck | Version data not supplied | |
Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3 | CVE List | WSR-2533DHPL2 <=1.02, WSR-2533DHP3 <= 1.24 | affected |
Nuclei templates
1ProjectDiscoveryHIGHBuffalo WSR-2533DHPL2 - Configuration File InjectionCVSS 8.8
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 does not properly sanitize user input. An authenticated remote attacker could leverage this vulnerability to alter device configuration, potentially leading to remote code execution.
Impact
An attacker can exploit this vulnerability to inject malicious configuration settings, potentially leading to unauthorized access or control of the router.
Remediation
Apply the latest firmware update provided by Buffalo to fix the configuration file injection vulnerability.
Source: ProjectDiscovery