CVE-2021-20092
buffalo wsr-2533dhpl2-bk_firmware Improper Authentication
Record summary
CVE-2021-20092 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unauthorized actor.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 25, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
wsr-2533dhpl2-bk_firmwareBrowse buffalo / wsr-2533dhpl2-bk_firmware | VulnCheck | Version data not supplied | |
Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3 | CVE List | WSR-2533DHPL2 <=1.02, WSR-2533DHP3 <= 1.24 | affected |
Nuclei templates
1ProjectDiscoveryHIGHBuffalo WSR-2533DHPL2 - Improper Access ControlCVSS 7.5
The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unauthorized actor.
Impact
An attacker can exploit this vulnerability to gain unauthorized access to the router's configuration settings and potentially compromise the entire network.
Remediation
Apply the latest firmware update provided by Buffalo to fix the access control issue.
Source: ProjectDiscovery