Description
Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 firmware Ver.2.32 and prior, WBR2-G54-KD firmware Ver.2.32 and prior, WBR-B11 firmware Ver.2.23 and prior, WBR-G54 firmware Ver.2.23 and prior, WBR-G54L firmware Ver.2.20 and prior, WHR2-A54G54 firmware Ver.2.25 and prior, WHR2-G54 firmware Ver.2.23 and prior, WHR2-G54V firmware Ver.2.55 and prior, WHR3-AG54 firmware Ver.2.23 and prior, WHR-G54 firmware Ver.2.16 and prior, WHR-G54-NF firmware Ver.2.10 and prior, WLA2-G54 firmware Ver.2.24 and prior, WLA2-G54C firmware Ver.2.24 and prior, WLA-B11 firmware Ver.2.20 and prior, WLA-G54 firmware Ver.2.20 and prior, WLA-G54C firmware Ver.2.20 and prior, WLAH-A54G54 firmware Ver.2.54 and prior, WLAH-AM54G54 firmware Ver.2.54 and prior, WLAH-G54 firmware Ver.2.54 and prior, WLI2-TX1-AG54 firmware Ver.2.53 and prior, WLI2-TX1-AMG54 firmware Ver.2.53 and prior, WLI2-TX1-G54 firmware Ver.2.20 and prior, WLI3-TX1-AMG54 firmware Ver.2.53 and prior, WLI3-TX1-G54 firmware Ver.2.53 and prior, WLI-T1-B11 firmware Ver.2.20 and prior, WLI-TX1-G54 firmware Ver.2.20 and prior, WVR-G54-NF firmware Ver.2.02 and prior, WZR-G108 firmware Ver.2.41 and prior, WZR-G54 firmware Ver.2.41 and prior, WZR-HP-G54 firmware Ver.2.41 and prior, WZR-RS-G54 firmware Ver.2.55 and prior, and WZR-RS-G54HP firmware Ver.2.55 and prior) allows a remote attacker to enable the debug option and to execute arbitrary code or OS commands, change the configuration, and cause a denial of service (DoS) condition.
Published: 2021-04-28
Score: 9.8 Critical
EPSS: 3.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-8131 Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 firmware Ver.2.32 and prior, WBR2-G54-KD firmware Ver.2.32 and prior, WBR-B11 firmware Ver.2.23 and prior, WBR-G54 firmware Ver.2.23 and prior, WBR-G54L firmware Ver.2.20 and prior, WHR2-A54G54 firmware Ver.2.25 and prior, WHR2-G54 firmware Ver.2.23 and prior, WHR2-G54V firmware Ver.2.55 and prior, WHR3-AG54 firmware Ver.2.23 and prior, WHR-G54 firmware Ver.2.16 and prior, WHR-G54-NF firmware Ver.2.10 and prior, WLA2-G54 firmware Ver.2.24 and prior, WLA2-G54C firmware Ver.2.24 and prior, WLA-B11 firmware Ver.2.20 and prior, WLA-G54 firmware Ver.2.20 and prior, WLA-G54C firmware Ver.2.20 and prior, WLAH-A54G54 firmware Ver.2.54 and prior, WLAH-AM54G54 firmware Ver.2.54 and prior, WLAH-G54 firmware Ver.2.54 and prior, WLI2-TX1-AG54 firmware Ver.2.53 and prior, WLI2-TX1-AMG54 firmware Ver.2.53 and prior, WLI2-TX1-G54 firmware Ver.2.20 and prior, WLI3-TX1-AMG54 firmware Ver.2.53 and prior, WLI3-TX1-G54 firmware Ver.2.53 and prior, WLI-T1-B11 firmware Ver.2.20 and prior, WLI-TX1-G54 firmware Ver.2.20 and prior, WVR-G54-NF firmware Ver.2.02 and prior, WZR-G108 firmware Ver.2.41 and prior, WZR-G54 firmware Ver.2.41 and prior, WZR-HP-G54 firmware Ver.2.41 and prior, WZR-RS-G54 firmware Ver.2.55 and prior, and WZR-RS-G54HP firmware Ver.2.55 and prior) allows a remote attacker to enable the debug option and to execute arbitrary code or OS commands, change the configuration, and cause a denial of service (DoS) condition.
History

No history.

Subscriptions

Buffalo Bhr-4rv Bhr-4rv Firmware Fs-g54 Fs-g54 Firmware Wbr-b11 Wbr-b11 Firmware Wbr-g54 Wbr-g54 Firmware Wbr-g54l Wbr-g54l Firmware Wbr2-b11 Wbr2-b11 Firmware Wbr2-g54 Wbr2-g54-kd Wbr2-g54-kd Firmware Wbr2-g54 Firmware Whr-g54 Whr-g54-nf Whr-g54-nf Firmware Whr-g54 Firmware Whr2-a54g54 Whr2-a54g54 Firmware Whr2-g54 Whr2-g54 Firmware Whr2-g54v Whr2-g54v Firmware Whr3-ag54 Whr3-ag54 Firmware Wla-b11 Wla-b11 Firmware Wla-g54 Wla-g54 Firmware Wla-g54c Wla-g54c Firmware Wla2-g54 Wla2-g54 Firmware Wla2-g54c Wla2-g54c Firmware Wlah-a54g54 Wlah-a54g54 Firmware Wlah-am54g54 Wlah-am54g54 Firmware Wlah-g54 Wlah-g54 Firmware Wli-t1-b11 Wli-t1-b11 Firmware Wli-tx1-g54 Wli-tx1-g54 Firmware Wli2-tx1-ag54 Wli2-tx1-ag54 Firmware Wli2-tx1-amg54 Wli2-tx1-amg54 Firmware Wli2-tx1-g54 Wli2-tx1-g54 Firmware Wli3-tx1-amg54 Wli3-tx1-amg54 Firmware Wli3-tx1-g54 Wli3-tx1-g54 Firmware Wvr-g54-nf Wvr-g54-nf Firmware Wzr-g108 Wzr-g108 Firmware Wzr-g54 Wzr-g54 Firmware Wzr-hp-g54 Wzr-hp-g54 Firmware Wzr-rs-g54 Wzr-rs-g54 Firmware Wzr-rs-g54hp Wzr-rs-g54hp Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-08-03T17:53:21.257Z

Reserved: 2020-12-17T00:00:00.000Z

Link: CVE-2021-20716

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-28T01:15:17.107

Modified: 2024-11-21T05:47:03.950

Link: CVE-2021-20716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses