CVE-2021-20090
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
29/04/2021
Last modified:
19/03/2025
Description
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:buffalo:wsr-2533dhpl2-bk_firmware:*:*:*:*:*:*:*:* | 1.02 (including) | |
cpe:2.3:h:buffalo:wsr-2533dhpl2-bk:-:*:*:*:*:*:*:* | ||
cpe:2.3:o:buffalo:wsr-2533dhp3-bk_firmware:*:*:*:*:*:*:*:* | 1.24 (including) | |
cpe:2.3:h:buffalo:wsr-2533dhp3-bk:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://www.kb.cert.org/vuls/id/914124
- https://www.secpod.com/blog/arcadyan-based-routers-and-modems-under-active-exploitation/
- https://www.tenable.com/security/research/tra-2021-13
- https://www.kb.cert.org/vuls/id/914124
- https://www.secpod.com/blog/arcadyan-based-routers-and-modems-under-active-exploitation/
- https://www.tenable.com/security/research/tra-2021-13