RULE(RULE ID:333882)

Rule General Information
Release Date: 2021-08-10
Rule Name: Buffalo WSR-2533DHPL2/WSR-2533DHP3 Authentication Bypass Vulnerability (CVE-2021-20090)
Severity:
CVE ID:
Rule Protection Details
Description: A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version 1.02 and WSR-2533DHP3 firmware version 1.24 could allow unauthenticated remote attackers to bypass authentication.
Impact: An attacker can take advantage of the vulnerability to bypass the security policy implemented by the software administrator, and perform unauthorized actions to the target system.
Affected OS: Windows, Others
Reference: https://www.kb.cert.org/vuls/id/914124
https://www.tenable.com/security/research/tra-2021-13
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.buffalo.jp/news/detail/20210427-03.html