CVE-2021-20090KEV · OVERDUE

Arcadyan Buffalo Firmware Path Traversal Vulnerability

Critical · published April 29, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it critical at 9.8. It is confirmed in active exploitation. It sits in the 100.0th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
9.8
EPSS
100%
Percentile
100.0
In the wild
Confirmed
What it is

🚨 A sneaky path traversal vulnerability could let attackers waltz right through your defenses! An unauthenticated remote user can access sensitive data on Buffalo routers running outdated firmware! 🔥 Think of this like a delivery driver who’s given a map with all the wrong turns marked clearly. Instead of following the address, they take a shortcut through your backyard, accessing every nook and cranny of your privacy without permission! An attacker could bypass authentication entirely and access sensitive information stored on your router — it's like leaving your front door wide open, inviting anyone to come in and snoop around. This could lead to data breaches, privacy violations, and potential network hijacking, putting you and your devices at significant risk!

Put simply

Think of this like a delivery driver who’s given a map with all the wrong turns marked clearly. Instead of following the address, they take a shortcut through your backyard, accessing every nook and cranny of your privacy without permission! This path traversal vulnerability allows attackers to exploit the web interface of specific Buffalo router firmware versions, enabling them to bypass security checks and access unauthorized directories and files directly.

What to do

An attacker could bypass authentication entirely and access sensitive information stored on your router — it's like leaving your front door wide open, inviting anyone to come in and snoop around. This could lead to data breaches, privacy violations, and potential network hijacking, putting you and your devices at significant risk! Update your Buffalo router firmware immediately to versions 1.03 or 1.25 or higher, ensuring proper security protocols are in place. Additionally, consider disabling remote management features if they’re not necessary for your setup. Regularly check for firmware updates to keep your devices secure! This is fixable! Stay proactive and secure your network with these steps. You’ve got this! 🛡️

The record
Technical detail
CVSS v3.1
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.99983 · 100.0th percentile
Published
2021-04-29T00:00Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 29 APR 00:00Z
    A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow…
    cvelistv5