Skip to content
COOEY

EXPOSURES › CVE-2021-20090

CVE-2021-20090

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-20090 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatched

Arcadyan Buffalo firmware path traversal flaw lets unauthenticated attackers bypass authentication and read sensitive data.

A path traversal vulnerability in Arcadyan Buffalo firmware allows remote, unauthenticated attackers to bypass authentication and access sensitive information on affected routers. This is a high-embarrassment failure because it involves a known, actively exploited (KEV) vulnerability that was left unpatched, exposing networks to data exfiltration and compliance violations. DIB organizations must ensure all network hardware is patched and monitored for KEV entries to prevent similar exposures.

Shame score — The vulnerability was actively exploited in the wild (KEV) and left unpatched, allowing unauthenticated attackers to bypass authentication and access sensitive data, representing a negligent failure to protect network infrastructure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.70
Widespread acknowledgement of a significant vulnerability with potential for exploitation, highlighting Arcadyan's responsibility.
cooey ↗ severe-fallout -0.80
Neutral reporting of the vulnerability's technical details.
"Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information."
app.opencve.io ↗ severe-fallout +0.00
No mention of Arcadyan or the vulnerability.
"CVEs and Security Vulnerabilities - OpenCVE"
www.cvefind.com ↗ severe-fallout +0.00
No mention of Arcadyan or the vulnerability.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
talosintelligence.com ↗ severe-fallout +0.00
No mention of Arcadyan or the vulnerability.
"Vulnerability Reports - Latest network security threats and zeroday discoveries"
cvedb.shodan.io ↗ severe-fallout +0.00
No mention of Arcadyan or the vulnerability.
"The CVEDB API offers a quick way to check information about vulnerabilities in a service."
cvefeed.io ↗ severe-fallout +0.00
No mention of Arcadyan or the vulnerability.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
xposedornot.com ↗ severe-fallout +0.00
No mention of Arcadyan or the vulnerability.
"Browse 766 breaches across 20 industries."
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.