Description
Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 firmware Ver.2.32 and prior, WBR2-G54-KD firmware Ver.2.32 and prior, WBR-B11 firmware Ver.2.23 and prior, WBR-G54 firmware Ver.2.23 and prior, WBR-G54L firmware Ver.2.20 and prior, WHR2-A54G54 firmware Ver.2.25 and prior, WHR2-G54 firmware Ver.2.23 and prior, WHR2-G54V firmware Ver.2.55 and prior, WHR3-AG54 firmware Ver.2.23 and prior, WHR-G54 firmware Ver.2.16 and prior, WHR-G54-NF firmware Ver.2.10 and prior, WLA2-G54 firmware Ver.2.24 and prior, WLA2-G54C firmware Ver.2.24 and prior, WLA-B11 firmware Ver.2.20 and prior, WLA-G54 firmware Ver.2.20 and prior, WLA-G54C firmware Ver.2.20 and prior, WLAH-A54G54 firmware Ver.2.54 and prior, WLAH-AM54G54 firmware Ver.2.54 and prior, WLAH-G54 firmware Ver.2.54 and prior, WLI2-TX1-AG54 firmware Ver.2.53 and prior, WLI2-TX1-AMG54 firmware Ver.2.53 and prior, WLI2-TX1-G54 firmware Ver.2.20 and prior, WLI3-TX1-AMG54 firmware Ver.2.53 and prior, WLI3-TX1-G54 firmware Ver.2.53 and prior, WLI-T1-B11 firmware Ver.2.20 and prior, WLI-TX1-G54 firmware Ver.2.20 and prior, WVR-G54-NF firmware Ver.2.02 and prior, WZR-G108 firmware Ver.2.41 and prior, WZR-G54 firmware Ver.2.41 and prior, WZR-HP-G54 firmware Ver.2.41 and prior, WZR-RS-G54 firmware Ver.2.55 and prior, and WZR-RS-G54HP firmware Ver.2.55 and prior) allows a remote attacker to enable the debug option and to execute arbitrary code or OS commands, change the configuration, and cause a denial of service (DoS) condition.
Published: 2021-04-28
Score: 9.8 Critical
EPSS: 3.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-8131 Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 firmware Ver.2.32 and prior, WBR2-G54-KD firmware Ver.2.32 and prior, WBR-B11 firmware Ver.2.23 and prior, WBR-G54 firmware Ver.2.23 and prior, WBR-G54L firmware Ver.2.20 and prior, WHR2-A54G54 firmware Ver.2.25 and prior, WHR2-G54 firmware Ver.2.23 and prior, WHR2-G54V firmware Ver.2.55 and prior, WHR3-AG54 firmware Ver.2.23 and prior, WHR-G54 firmware Ver.2.16 and prior, WHR-G54-NF firmware Ver.2.10 and prior, WLA2-G54 firmware Ver.2.24 and prior, WLA2-G54C firmware Ver.2.24 and prior, WLA-B11 firmware Ver.2.20 and prior, WLA-G54 firmware Ver.2.20 and prior, WLA-G54C firmware Ver.2.20 and prior, WLAH-A54G54 firmware Ver.2.54 and prior, WLAH-AM54G54 firmware Ver.2.54 and prior, WLAH-G54 firmware Ver.2.54 and prior, WLI2-TX1-AG54 firmware Ver.2.53 and prior, WLI2-TX1-AMG54 firmware Ver.2.53 and prior, WLI2-TX1-G54 firmware Ver.2.20 and prior, WLI3-TX1-AMG54 firmware Ver.2.53 and prior, WLI3-TX1-G54 firmware Ver.2.53 and prior, WLI-T1-B11 firmware Ver.2.20 and prior, WLI-TX1-G54 firmware Ver.2.20 and prior, WVR-G54-NF firmware Ver.2.02 and prior, WZR-G108 firmware Ver.2.41 and prior, WZR-G54 firmware Ver.2.41 and prior, WZR-HP-G54 firmware Ver.2.41 and prior, WZR-RS-G54 firmware Ver.2.55 and prior, and WZR-RS-G54HP firmware Ver.2.55 and prior) allows a remote attacker to enable the debug option and to execute arbitrary code or OS commands, change the configuration, and cause a denial of service (DoS) condition.
History

No history.

Subscriptions

Buffalo Bhr-4rv Bhr-4rv Firmware Fs-g54 Fs-g54 Firmware Wbr-b11 Wbr-b11 Firmware Wbr-g54 Wbr-g54 Firmware Wbr-g54l Wbr-g54l Firmware Wbr2-b11 Wbr2-b11 Firmware Wbr2-g54 Wbr2-g54-kd Wbr2-g54-kd Firmware Wbr2-g54 Firmware Whr-g54 Whr-g54-nf Whr-g54-nf Firmware Whr-g54 Firmware Whr2-a54g54 Whr2-a54g54 Firmware Whr2-g54 Whr2-g54 Firmware Whr2-g54v Whr2-g54v Firmware Whr3-ag54 Whr3-ag54 Firmware Wla-b11 Wla-b11 Firmware Wla-g54 Wla-g54 Firmware Wla-g54c Wla-g54c Firmware Wla2-g54 Wla2-g54 Firmware Wla2-g54c Wla2-g54c Firmware Wlah-a54g54 Wlah-a54g54 Firmware Wlah-am54g54 Wlah-am54g54 Firmware Wlah-g54 Wlah-g54 Firmware Wli-t1-b11 Wli-t1-b11 Firmware Wli-tx1-g54 Wli-tx1-g54 Firmware Wli2-tx1-ag54 Wli2-tx1-ag54 Firmware Wli2-tx1-amg54 Wli2-tx1-amg54 Firmware Wli2-tx1-g54 Wli2-tx1-g54 Firmware Wli3-tx1-amg54 Wli3-tx1-amg54 Firmware Wli3-tx1-g54 Wli3-tx1-g54 Firmware Wvr-g54-nf Wvr-g54-nf Firmware Wzr-g108 Wzr-g108 Firmware Wzr-g54 Wzr-g54 Firmware Wzr-hp-g54 Wzr-hp-g54 Firmware Wzr-rs-g54 Wzr-rs-g54 Firmware Wzr-rs-g54hp Wzr-rs-g54hp Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-08-03T17:53:21.257Z

Reserved: 2020-12-17T00:00:00.000Z

Link: CVE-2021-20716

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-04-28T01:15:17.107

Modified: 2024-11-21T05:47:03.950

Link: CVE-2021-20716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses