Executive brief
A path traversal vulnerability in the web interfaces of certain Buffalo router firmware allows unauthenticated remote attackers to bypass authentication. This flaw can be leveraged to access sensitive information and has been observed in active exploitation.
Affected products
- Buffalo WSR-2533DHPL2 firmware <= 1.02
- Buffalo WSR-2533DHP3 firmware <= 1.24
Timeline
- 2021-04-29: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: Publication date of the provided advisory
- 2021-11-03: exploited: Reported as exploited in the wild in the advisory and CISA KEV catalog