CVE-2021-20716

Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 firmware Ver.2.32 and prior, WBR2-G54-KD firmware Ver.2.32 and prior, WBR-B11 firmware Ver.2.23 and prior, WBR-G54 firmware Ver.2.23 and prior, WBR-G54L firmware Ver.2.20 and prior, WHR2-A54G54 firmware Ver.2.25 and prior, WHR2-G54 firmware Ver.2.23 and prior, WHR2-G54V firmware Ver.2.55 and prior, WHR3-AG54 firmware Ver.2.23 and prior, WHR-G54 firmware Ver.2.16 and prior, WHR-G54-NF firmware Ver.2.10 and prior, WLA2-G54 firmware Ver.2.24 and prior, WLA2-G54C firmware Ver.2.24 and prior, WLA-B11 firmware Ver.2.20 and prior, WLA-G54 firmware Ver.2.20 and prior, WLA-G54C firmware Ver.2.20 and prior, WLAH-A54G54 firmware Ver.2.54 and prior, WLAH-AM54G54 firmware Ver.2.54 and prior, WLAH-G54 firmware Ver.2.54 and prior, WLI2-TX1-AG54 firmware Ver.2.53 and prior, WLI2-TX1-AMG54 firmware Ver.2.53 and prior, WLI2-TX1-G54 firmware Ver.2.20 and prior, WLI3-TX1-AMG54 firmware Ver.2.53 and prior, WLI3-TX1-G54 firmware Ver.2.53 and prior, WLI-T1-B11 firmware Ver.2.20 and prior, WLI-TX1-G54 firmware Ver.2.20 and prior, WVR-G54-NF firmware Ver.2.02 and prior, WZR-G108 firmware Ver.2.41 and prior, WZR-G54 firmware Ver.2.41 and prior, WZR-HP-G54 firmware Ver.2.41 and prior, WZR-RS-G54 firmware Ver.2.55 and prior, and WZR-RS-G54HP firmware Ver.2.55 and prior) allows a remote attacker to enable the debug option and to execute arbitrary code or OS commands, change the configuration, and cause a denial of service (DoS) condition.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:buffalo:bhr-4rv_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bhr-4rv:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:buffalo:fs-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:fs-g54:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:buffalo:wbr2-b11_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wbr2-b11:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:buffalo:wbr2-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wbr2-g54:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:buffalo:wbr2-g54-kd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wbr2-g54-kd:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:buffalo:wbr-b11_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wbr-b11:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:buffalo:wbr-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wbr-g54:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:buffalo:wbr-g54l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wbr-g54l:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:buffalo:whr2-a54g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:whr2-a54g54:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:buffalo:whr2-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:whr2-g54:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:buffalo:whr2-g54v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:whr2-g54v:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:buffalo:whr3-ag54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:whr3-ag54:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:buffalo:whr-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:whr-g54:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:buffalo:whr-g54-nf_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:whr-g54-nf:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:buffalo:wla2-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wla2-g54:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:buffalo:wla2-g54c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wla2-g54c:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:buffalo:wla-b11_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wla-b11:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:buffalo:wla-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wla-g54:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:buffalo:wla-g54c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wla-g54c:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:buffalo:wlah-a54g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wlah-a54g54:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:buffalo:wlah-am54g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wlah-am54g54:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:buffalo:wlah-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wlah-g54:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:buffalo:wli2-tx1-ag54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli2-tx1-ag54:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:buffalo:wli2-tx1-amg54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli2-tx1-amg54:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:buffalo:wli2-tx1-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli2-tx1-g54:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:buffalo:wli3-tx1-amg54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli3-tx1-amg54:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:buffalo:wli3-tx1-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli3-tx1-g54:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:buffalo:wli-t1-b11_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli-t1-b11:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:buffalo:wli-tx1-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli-tx1-g54:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:buffalo:wvr-g54-nf_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wvr-g54-nf:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:buffalo:wzr-g108_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wzr-g108:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:buffalo:wzr-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wzr-g54:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:buffalo:wzr-hp-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wzr-hp-g54:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:buffalo:wzr-rs-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wzr-rs-g54:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:buffalo:wzr-rs-g54hp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wzr-rs-g54hp:-:*:*:*:*:*:*:*

History

07 May 2021, 17:43

Type Values Removed Values Added
References (MISC) https://jvn.jp/en/vu/JVNVU90274525/index.html - (MISC) https://jvn.jp/en/vu/JVNVU90274525/index.html - Third Party Advisory
References (MISC) https://www.buffalo.jp/news/detail/20210427-02.html - (MISC) https://www.buffalo.jp/news/detail/20210427-02.html - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 10.0
v3 : 9.8
CWE NVD-CWE-Other
CPE cpe:2.3:o:buffalo:fs-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wlah-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wbr2-b11_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wla-g54c:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wlah-g54:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli2-tx1-amg54:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wzr-rs-g54:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:fs-g54:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli2-tx1-ag54:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wlah-am54g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wzr-hp-g54:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wbr-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wla-g54:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wli2-tx1-ag54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wli3-tx1-amg54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wvr-g54-nf:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:whr2-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wbr-b11:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wlah-a54g54:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wbr2-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wzr-hp-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:whr-g54-nf:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wla-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wla2-g54c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wzr-g108_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli3-tx1-amg54:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli2-tx1-g54:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:bhr-4rv:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:whr-g54-nf_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wbr2-g54-kd:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wla-b11_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wli2-tx1-amg54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:whr2-a54g54:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wzr-g108:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wzr-rs-g54hp:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wbr-g54l:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wla-b11:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wvr-g54-nf_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wzr-g54:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wbr2-g54:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wli-tx1-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wbr-g54:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:whr-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wli2-tx1-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:whr2-g54v_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:whr-g54:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wli3-tx1-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:bhr-4rv_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wla2-g54:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:whr3-ag54:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli-t1-b11:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wzr-rs-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:whr2-g54:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wbr-g54l_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli3-tx1-g54:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wbr2-g54-kd_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wzr-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:whr2-a54g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:whr3-ag54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wzr-rs-g54hp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wla2-g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wbr2-b11:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wlah-a54g54_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wli-t1-b11_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:whr2-g54v:-:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wla2-g54c:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wla-g54c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wli-tx1-g54:-:*:*:*:*:*:*:*
cpe:2.3:o:buffalo:wbr-b11_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:buffalo:wlah-am54g54:-:*:*:*:*:*:*:*

28 Apr 2021, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-04-28 01:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-20716

Mitre link : CVE-2021-20716

CVE.ORG link : CVE-2021-20716


JSON object : View

Products Affected

buffalo

  • bhr-4rv
  • wla-g54c
  • wbr2-g54_firmware
  • fs-g54_firmware
  • wzr-g108_firmware
  • wli-t1-b11_firmware
  • wla2-g54c
  • wzr-rs-g54hp_firmware
  • wla2-g54_firmware
  • wbr2-g54
  • wli-tx1-g54_firmware
  • whr2-g54v
  • wbr-b11
  • wla-g54
  • wzr-g54_firmware
  • wvr-g54-nf
  • whr2-g54v_firmware
  • fs-g54
  • wla-b11
  • whr2-a54g54
  • wbr-g54l_firmware
  • wlah-am54g54_firmware
  • wla-b11_firmware
  • wli2-tx1-ag54_firmware
  • whr3-ag54
  • whr2-g54_firmware
  • whr-g54-nf_firmware
  • wbr2-b11_firmware
  • wli2-tx1-amg54_firmware
  • wbr-b11_firmware
  • wlah-g54
  • wli-t1-b11
  • wbr2-b11
  • wzr-rs-g54
  • whr-g54
  • wlah-a54g54_firmware
  • wli2-tx1-g54_firmware
  • wli-tx1-g54
  • whr3-ag54_firmware
  • wbr2-g54-kd
  • wvr-g54-nf_firmware
  • wzr-rs-g54hp
  • wlah-g54_firmware
  • wli3-tx1-amg54_firmware
  • wzr-g54
  • whr2-a54g54_firmware
  • wla2-g54
  • wla2-g54c_firmware
  • wlah-a54g54
  • wli3-tx1-g54
  • wzr-rs-g54_firmware
  • wbr-g54l
  • whr2-g54
  • wbr2-g54-kd_firmware
  • wli2-tx1-ag54
  • wla-g54c_firmware
  • wzr-hp-g54_firmware
  • whr-g54-nf
  • wla-g54_firmware
  • wbr-g54
  • wli2-tx1-g54
  • wli3-tx1-g54_firmware
  • wzr-g108
  • wli3-tx1-amg54
  • bhr-4rv_firmware
  • whr-g54_firmware
  • wbr-g54_firmware
  • wzr-hp-g54
  • wlah-am54g54
  • wli2-tx1-amg54