← Vulnerability feed

Vulnerability record · CVE-2021-20090 · published 29 April 2021

CVE-2021-20090: Buffalo router web interface path traversal allows auth bypass

Buffalo · Wsr 2533dhpl2 Bk Firmware

The web interface of Buffalo WSR-2533DHPL2 (firmware <= 1.02) and WSR-2533DHP3 (firmware <= 1.24) is vulnerable to path traversal (CWE-22). An unauthenticated remote attacker can use the traversal to bypass authentication on the device's web management interface. Because these are edge devices, a bypass exposes the router itself and the network behind it.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 100% · top 0.1% CWE-22 · Path traversal
9.8CVSS 3.1 base score, v2 7.5
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
7References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityCVSS 9.8, unauthenticated network reachability, KEV listing with a past remediation deadline and near-maximum EPSS make this an urgent edge-device fix.

What it is

The web interface of Buffalo WSR-2533DHPL2 (firmware <= 1.02) and WSR-2533DHP3 (firmware <= 1.24) is vulnerable to path traversal (CWE-22). An unauthenticated remote attacker can use the traversal to bypass authentication on the device's web management interface. Because these are edge devices, a bypass exposes the router itself and the network behind it.

Impact

An attacker gains unauthenticated access to the router's web interface, effectively taking over device management and enabling further compromise of the network behind it. The CVSS 3.1 vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reachable over the network via the device web interface (AV:N, PR:N, UI:N), so no credentials or user interaction are required. The flaw is in the web interface itself, so any internet- or LAN-exposed management interface is a candidate path.

Exploitation

CISA added it to KEV on 2021-11-03 with a 2021-11-17 remediation due, and references carry Exploit tags; EPSS 30-day probability is 0.99983 (99.98th percentile). No ransomware campaign use is documented in the record.

What to do

  • Apply the vendor firmware updates for WSR-2533DHPL2 and WSR-2533DHP3 per vendor instructions (CISA KEV required action).
  • If patching is not immediately possible, remove the web management interface from untrusted exposure (disable remote/WAN administration, restrict to a trusted management segment).
  • Isolate affected devices on a segmented network until they are updated.
  • Replace devices that no longer receive firmware support.
  • Verify the update actually applied and re-check exposure of the management interface.

Detection

  • Monitor web interface access logs on affected Buffalo devices for traversal-style request paths and unexpected unauthenticated requests.
  • Alert on management-interface logins or configuration changes from unexpected source addresses.
  • Watch network traffic to the device web interface from external or non-management networks.
  • Hunt for post-exploitation changes to router configuration, DNS settings or firmware.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-20090 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Arcadyan Buffalo Firmware Path Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-20090 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-20091Buffalo wsr-2533dhpl2-bk firmware vulnerabilityThe web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input. A…EPSS 8.8%7.5CVE-2021-20092Buffalo wsr-2533dhpl2-bk firmware improper authentication vulnerabilityThe web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly restrict access to sen…EPSS 8.2%9.8CVE-2026-93616Checkpoint multi-domain security management path traversal vulnerabilityA directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Managem…KEVEPSS 20%10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed5.3CVE-2026-66384JFrog Artifactory path traversal in Docker cache pathAn authenticated user can write data outside the intended Docker cache path under specific remote-repository conditions in JFrog Artifactory. The fla…KEVEPSS 0.66%analysed9.8CVE-2026-59310VMware vCenter Syslog server path traversal leads to RCEVMware vCenter's Syslog server is affected by a directory traversal flaw (CWE-22) that allows a remote, unauthenticated attacker to execute arbitrary…KEVEPSS 2.6%analysed10.0CVE-2026-48282Adobe ColdFusion path traversal leads to remote code executionColdFusion versions 2025.9, 2023.20 and earlier contain a path traversal flaw (CWE-22) that allows an unauthenticated remote attacker to reach files …KEVEPSS 42%analysed10.0CVE-2026-34909UniFi OS path traversal allows unauthenticated file accessUniFi OS devices contain a path traversal flaw (CWE-22) that lets a network-reachable attacker read files on the underlying system. Because the expos…KEVEPSS 1.8%analysed

Source: NIST National Vulnerability Database (record CVE-2021-20090), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.