Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP firmware Ver.1.99 and prior, WHR-300 firmware Ver.1.99 and prior, WHR-G301N firmware Ver.1.86 and prior, WHR-HP-G300N firmware Ver.1.99 and prior, WHR-HP-GN firmware Ver.1.86 and prior, WPL-05G300 firmware Ver.1.87 and prior, WZR-450HP-CWT firmware Ver.1.99 and prior, WZR-450HP-UB firmware Ver.1.99 and prior, WZR-HP-AG300H firmware Ver.1.75 and prior, WZR-HP-G300NH firmware Ver.1.83 and prior, WZR-HP-G301NH firmware Ver.1.83 and prior, WZR-HP-G302H firmware Ver.1.85 and prior, WZR-HP-G450H firmware Ver.1.89 and prior, WZR-300HP firmware Ver.1.99 and prior, WZR-450HP firmware Ver.1.99 and prior, WZR-600DHP firmware Ver.1.99 and prior, WZR-D1100H firmware Ver.1.99 and prior, FS-HP-G300N firmware Ver.3.32 and prior, FS-600DHP firmware Ver.3.38 and prior, FS-R600DHP firmware Ver.3.39 and prior, and FS-G300N firmware Ver.3.13 and prior) allows remote unauthenticated attackers to bypass access restriction and to start telnet service and execute arbitrary OS commands with root privileges via unspecified vectors.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Buffalo
Subscribe
|
Bhr-4grv
Subscribe
Bhr-4grv Firmware
Subscribe
Dwr-hp-g300nh
Subscribe
Dwr-hp-g300nh Firmware
Subscribe
Fs-600dhp
Subscribe
Fs-600dhp Firmware
Subscribe
Fs-g300n
Subscribe
Fs-g300n Firmware
Subscribe
Fs-hp-g300n
Subscribe
Fs-hp-g300n Firmware
Subscribe
Fs-r600dhp
Subscribe
Fs-r600dhp Firmware
Subscribe
Hw-450hp-zwe
Subscribe
Hw-450hp-zwe Firmware
Subscribe
Whr-300
Subscribe
Whr-300 Firmware
Subscribe
Whr-300hp
Subscribe
Whr-300hp Firmware
Subscribe
Whr-g301n
Subscribe
Whr-g301n Firmware
Subscribe
Whr-hp-g300n
Subscribe
Whr-hp-g300n Firmware
Subscribe
Whr-hp-gn
Subscribe
Whr-hp-gn Firmware
Subscribe
Wpl-05g300
Subscribe
Wpl-05g300 Firmware
Subscribe
Wzr-300hp
Subscribe
Wzr-300hp Firmware
Subscribe
Wzr-450hp
Subscribe
Wzr-450hp-cwt
Subscribe
Wzr-450hp-cwt Firmware
Subscribe
Wzr-450hp-ub
Subscribe
Wzr-450hp-ub Firmware
Subscribe
Wzr-450hp Firmware
Subscribe
Wzr-600dhp
Subscribe
Wzr-600dhp Firmware
Subscribe
Wzr-d1100h
Subscribe
Wzr-d1100h Firmware
Subscribe
Wzr-hp-ag300h
Subscribe
Wzr-hp-ag300h Firmware
Subscribe
Wzr-hp-g300nh
Subscribe
Wzr-hp-g300nh Firmware
Subscribe
Wzr-hp-g301nh
Subscribe
Wzr-hp-g301nh Firmware
Subscribe
Wzr-hp-g302h
Subscribe
Wzr-hp-g302h Firmware
Subscribe
Wzr-hp-g450h
Subscribe
Wzr-hp-g450h Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-26831 | Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP firmware Ver.1.99 and prior, WHR-300 firmware Ver.1.99 and prior, WHR-G301N firmware Ver.1.86 and prior, WHR-HP-G300N firmware Ver.1.99 and prior, WHR-HP-GN firmware Ver.1.86 and prior, WPL-05G300 firmware Ver.1.87 and prior, WZR-450HP-CWT firmware Ver.1.99 and prior, WZR-450HP-UB firmware Ver.1.99 and prior, WZR-HP-AG300H firmware Ver.1.75 and prior, WZR-HP-G300NH firmware Ver.1.83 and prior, WZR-HP-G301NH firmware Ver.1.83 and prior, WZR-HP-G302H firmware Ver.1.85 and prior, WZR-HP-G450H firmware Ver.1.89 and prior, WZR-300HP firmware Ver.1.99 and prior, WZR-450HP firmware Ver.1.99 and prior, WZR-600DHP firmware Ver.1.99 and prior, WZR-D1100H firmware Ver.1.99 and prior, FS-HP-G300N firmware Ver.3.32 and prior, FS-600DHP firmware Ver.3.38 and prior, FS-R600DHP firmware Ver.3.39 and prior, and FS-G300N firmware Ver.3.13 and prior) allows remote unauthenticated attackers to bypass access restriction and to start telnet service and execute arbitrary OS commands with root privileges via unspecified vectors. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jpcert
Published:
Updated: 2024-08-03T16:53:17.975Z
Reserved: 2021-04-22T00:00:00
Link: CVE-2021-3512
No data.
Status : Modified
Published: 2021-04-28T01:15:17.187
Modified: 2024-11-21T06:21:43.343
Link: CVE-2021-3512
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD