S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-20091 Scanner

CVE-2021-20091 scanner - Remote Code Execution (RCE) vulnerability in Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.2k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-20091
8.8
CVSS

The web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 do not properly sanitize user input. An authenticated remote attacker could leverage this vulnerability to alter device configuration, potentially gaining remote code execution.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
Buffalo WSR-2533DHPL2, Buffalo WSR-2533DHP3by n/a
WSR-2533DHPL2 <=1.02, WSR-2533DHP3 <= 1.24
Updated Aug 21, 2026View on NVD →
Detail

The Buffalo WSR-2533DHPL2 and WSR-2533DHP3 are high-performance routers that are widely used by businesses and home users. These routers are known for their advanced security features and high-speed connectivity, making them a popular choice among users who require a stable and secure network connection. 

Recently, a critical vulnerability has been discovered in the firmware versions of the Buffalo WSR-2533DHPL2 and WSR-2533DHP3 routers. Referred to as CVE-2021-20091, this vulnerability arises due to the routers not appropriately sanitizing user input, which opens up the possibility for an authenticated remote attacker to potentially gain remote code execution, resulting in the attacker being able to modify device configurations.

If an attacker gains access to a router system using this vulnerability, they may be able to steal sensitive information such as private data and network passwords, leading to a serious breach of security. Moreover, attackers may be able to install malicious software or firmware on the router, leading to severe damage to the device and, as a result, the compromise of the entire network.

Thanks to the pro features of the s4e.io platform, users can quickly scan their digital assets to detect any vulnerabilities that may exist, including those found in the Buffalo WSR-2533DHPL2 and WSR-2533DHP3 routers. This platform offers users an easy and quick way to get comprehensive security scans and reporting on vulnerabilities, assisting organizations in taking critical safety measures that can prevent them from becoming a victim to potential digital threats.

 

REFERENCES

Solution Advice

To prevent this vulnerability from being attacked, it is crucial to take some precautions. They include:

  • Installing the latest firmware updates released by the vendor regularly. This can help prevent the vulnerabilities found in previous firmware versions from being exploitable.
  • Regularly changing the default username and password for the router to a strong, unique, and complex combination that is difficult for the attacker to guess or crack.
  • Disabling remote management access to the router's administration interface. This ensures that the router is only manageable from the local network.
  • Enabling alerts or notifications for suspicious activities and monitoring the router log files for any unusual activity.
  • Using a network security solution, such as a firewall or intrusion detection system, to help detect and stop any unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.