EXPOSURES › CVE-2021-20090
CVE-2021-20090
HIGH ⌖ ON CISA KEV · EXPLOITEDArcadyan Buffalo firmware path traversal flaw lets unauthenticated attackers bypass authentication and read sensitive data.
A path traversal vulnerability in Arcadyan Buffalo firmware allows remote, unauthenticated attackers to bypass authentication and access sensitive information on affected routers. This is a high-embarrassment failure because it involves a known, actively exploited (KEV) vulnerability that was left unpatched, exposing networks to data exfiltration and compliance violations. DIB organizations must ensure all network hardware is patched and monitored for KEV entries to prevent similar exposures.
Shame score — The vulnerability was actively exploited in the wild (KEV) and left unpatched, allowing unauthenticated attackers to bypass authentication and access sensitive data, representing a negligent failure to protect network infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.
"Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information."
"CVEs and Security Vulnerabilities - OpenCVE"
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
"Vulnerability Reports - Latest network security threats and zeroday discoveries"
"The CVEDB API offers a quick way to check information about vulnerabilities in a service."
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
"Browse 766 breaches across 20 industries."