CVE-2021-20716
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/04/2021
Last modified:
07/05/2021
Description
Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 firmware Ver.2.32 and prior, WBR2-G54-KD firmware Ver.2.32 and prior, WBR-B11 firmware Ver.2.23 and prior, WBR-G54 firmware Ver.2.23 and prior, WBR-G54L firmware Ver.2.20 and prior, WHR2-A54G54 firmware Ver.2.25 and prior, WHR2-G54 firmware Ver.2.23 and prior, WHR2-G54V firmware Ver.2.55 and prior, WHR3-AG54 firmware Ver.2.23 and prior, WHR-G54 firmware Ver.2.16 and prior, WHR-G54-NF firmware Ver.2.10 and prior, WLA2-G54 firmware Ver.2.24 and prior, WLA2-G54C firmware Ver.2.24 and prior, WLA-B11 firmware Ver.2.20 and prior, WLA-G54 firmware Ver.2.20 and prior, WLA-G54C firmware Ver.2.20 and prior, WLAH-A54G54 firmware Ver.2.54 and prior, WLAH-AM54G54 firmware Ver.2.54 and prior, WLAH-G54 firmware Ver.2.54 and prior, WLI2-TX1-AG54 firmware Ver.2.53 and prior, WLI2-TX1-AMG54 firmware Ver.2.53 and prior, WLI2-TX1-G54 firmware Ver.2.20 and prior, WLI3-TX1-AMG54 firmware Ver.2.53 and prior, WLI3-TX1-G54 firmware Ver.2.53 and prior, WLI-T1-B11 firmware Ver.2.20 and prior, WLI-TX1-G54 firmware Ver.2.20 and prior, WVR-G54-NF firmware Ver.2.02 and prior, WZR-G108 firmware Ver.2.41 and prior, WZR-G54 firmware Ver.2.41 and prior, WZR-HP-G54 firmware Ver.2.41 and prior, WZR-RS-G54 firmware Ver.2.55 and prior, and WZR-RS-G54HP firmware Ver.2.55 and prior) allows a remote attacker to enable the debug option and to execute arbitrary code or OS commands, change the configuration, and cause a denial of service (DoS) condition.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:buffalo:bhr-4rv_firmware:*:*:*:*:*:*:*:* | 2.55 (including) | |
cpe:2.3:h:buffalo:bhr-4rv:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:buffalo:fs-g54_firmware:*:*:*:*:*:*:*:* | 2.04 (including) | |
cpe:2.3:h:buffalo:fs-g54:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:buffalo:wbr2-b11_firmware:*:*:*:*:*:*:*:* | 2.32 (including) | |
cpe:2.3:h:buffalo:wbr2-b11:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:buffalo:wbr2-g54_firmware:*:*:*:*:*:*:*:* | 2.32 (including) | |
cpe:2.3:h:buffalo:wbr2-g54:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:buffalo:wbr2-g54-kd_firmware:*:*:*:*:*:*:*:* | 2.32 (including) | |
cpe:2.3:h:buffalo:wbr2-g54-kd:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:buffalo:wbr-b11_firmware:*:*:*:*:*:*:*:* | 2.23 (including) | |
cpe:2.3:h:buffalo:wbr-b11:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:buffalo:wbr-g54_firmware:*:*:*:*:*:*:*:* | 2.23 (including) | |
cpe:2.3:h:buffalo:wbr-g54:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:buffalo:wbr-g54l_firmware:*:*:*:*:*:*:*:* | 2.20 (including) |
To consult the complete list of CPE names with products and versions, see this page