Vulnerability record · CVE-2021-20090 · published 29 April 2021
CVE-2021-20090: Buffalo router web interface path traversal allows auth bypass
Buffalo · Wsr 2533dhpl2 Bk Firmware
The web interface of Buffalo WSR-2533DHPL2 (firmware <= 1.02) and WSR-2533DHP3 (firmware <= 1.24) is vulnerable to path traversal (CWE-22). An unauthenticated remote attacker can use the traversal to bypass authentication on the device's web management interface. Because these are edge devices, a bypass exposes the router itself and the network behind it.
Description
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 could allow unauthenticated remote attackers to bypass authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated network reachability, KEV listing with a past remediation deadline and near-maximum EPSS make this an urgent edge-device fix.
What it is
The web interface of Buffalo WSR-2533DHPL2 (firmware <= 1.02) and WSR-2533DHP3 (firmware <= 1.24) is vulnerable to path traversal (CWE-22). An unauthenticated remote attacker can use the traversal to bypass authentication on the device's web management interface. Because these are edge devices, a bypass exposes the router itself and the network behind it.
Impact
An attacker gains unauthenticated access to the router's web interface, effectively taking over device management and enabling further compromise of the network behind it. The CVSS 3.1 vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reachable over the network via the device web interface (AV:N, PR:N, UI:N), so no credentials or user interaction are required. The flaw is in the web interface itself, so any internet- or LAN-exposed management interface is a candidate path.
Exploitation
CISA added it to KEV on 2021-11-03 with a 2021-11-17 remediation due, and references carry Exploit tags; EPSS 30-day probability is 0.99983 (99.98th percentile). No ransomware campaign use is documented in the record.
What to do
- Apply the vendor firmware updates for WSR-2533DHPL2 and WSR-2533DHP3 per vendor instructions (CISA KEV required action).
- If patching is not immediately possible, remove the web management interface from untrusted exposure (disable remote/WAN administration, restrict to a trusted management segment).
- Isolate affected devices on a segmented network until they are updated.
- Replace devices that no longer receive firmware support.
- Verify the update actually applied and re-check exposure of the management interface.
Detection
- Monitor web interface access logs on affected Buffalo devices for traversal-style request paths and unexpected unauthenticated requests.
- Alert on management-interface logins or configuration changes from unexpected source addresses.
- Watch network traffic to the device web interface from external or non-management networks.
- Hunt for post-exploitation changes to router configuration, DNS settings or firmware.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-20090 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Arcadyan Buffalo Firmware Path Traversal Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://www.kb.cert.org/vuls/id/914124 | Third Party AdvisoryUS Government Resource |
| https://www.secpod.com/blog/arcadyan-based-routers-and-modems-under-active-exploitation/ | ExploitThird Party Advisory |
| https://www.tenable.com/security/research/tra-2021-13 | ExploitThird Party Advisory |
| https://www.kb.cert.org/vuls/id/914124 | Third Party AdvisoryUS Government Resource |
| https://www.secpod.com/blog/arcadyan-based-routers-and-modems-under-active-exploitation/ | ExploitThird Party Advisory |
| https://www.tenable.com/security/research/tra-2021-13 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-20090 | US Government Resource |
Track CVE-2021-20090 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-20090), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.