Record summary

CVE-2021-20092 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unauthorized actor.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Feb 25, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3

CVE ListWSR-2533DHPL2 <=1.02, WSR-2533DHP3 <= 1.24affected

Nuclei templates

1
ProjectDiscoveryHIGHBuffalo WSR-2533DHPL2 - Improper Access ControlCVSS 7.5

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unauthorized actor.

Impact

An attacker can exploit this vulnerability to gain unauthorized access to the router's configuration settings and potentially compromise the entire network.

Remediation

Apply the latest firmware update provided by Buffalo to fix the access control issue.

WeaknessesCWE-287
Authorsgy741, pdteam, parth
Template tagscve2021cvebuffalofirmwareiottenablevkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:o:buffalo:wsr-2533dhpl2-bk_firmware:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

2