QID 731232

Date Published: 2024-03-14

QID 731232: Buffalo Router Authentication Bypass Vulnerability

A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version 1.02 and prior versions and WSR-2533DHP3 firmware version 1.24 and prior versions could allow unauthenticated remote attackers to bypass authentication.

Affected Versions:
Buffalo WSR-2533DHPL2 firmware version 1.02 and prior versions.
Buffalo WSR-2533DHP3 firmware version 1.24 and prior versions.

Note: This QID checks supports 'Buffalo WSR-2533DHPL2' and 'Buffalo WSR-2533DHP3' models only. QID Detection Logic(Unauthenticated):
This QID sends an HTTP GET request to the 'images/..%2finfo.html' endpoint and checks if the info.html is accessible or not. A vulnerable router will load the info.html which is otherwise inaccessible.

Successful exploitation of the vulnerability may allow a remote unauthenticated attacker to bypass authentication, leading to critical data loss.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Customers are advised to upgrade their routers to the latest version.
    Vendor References

    CVEs related to QID 731232

    Software Advisories
    Advisory ID Software Component Link
    NA URL Logo NA