CVE-2021-3512

moderate-risk
Published 2021-04-28

Improper access control vulnerability in Buffalo broadband routers (BHR-4GRV firmware Ver.1.99 and prior, DWR-HP-G300NH firmware Ver.1.83 and prior, HW-450HP-ZWE firmware Ver.1.99 and prior, WHR-300HP firmware Ver.1.99 and prior, WHR-300 firmware Ver.1.99 and prior, WHR-G301N firmware Ver.1.86 and prior, WHR-HP-G300N firmware Ver.1.99 and prior, WHR-HP-GN firmware Ver.1.86 and prior, WPL-05G300 firmware Ver.1.87 and prior, WZR-450HP-CWT firmware Ver.1.99 and prior, WZR-450HP-UB firmware Ver.1.99 and prior, WZR-HP-AG300H firmware Ver.1.75 and prior, WZR-HP-G300NH firmware Ver.1.83 and prior, WZR-HP-G301NH firmware Ver.1.83 and prior, WZR-HP-G302H firmware Ver.1.85 and prior, WZR-HP-G450H firmware Ver.1.89 and prior, WZR-300HP firmware Ver.1.99 and prior, WZR-450HP firmware Ver.1.99 and prior, WZR-600DHP firmware Ver.1.99 and prior, WZR-D1100H firmware Ver.1.99 and prior, FS-HP-G300N firmware Ver.3.32 and prior, FS-600DHP firmware Ver.3.38 and prior, FS-R600DHP firmware Ver.3.39 and prior, and FS-G300N firmware Ver.3.13 and prior) allows remote unauthenticated attackers to bypass access restriction and to start telnet service and execute arbitrary OS commands with root privileges via unspecified vectors.

Do I need to act?

-
0.24% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10 High
ADJACENT_NETWORK / LOW complexity

Affected Products (20)

Bhr-4Grv Firmware
Dwr-Hp-G300Nh Firmware
Hw-450Hp-Zwe Firmware
Whr-300Hp Firmware
Whr-300 Firmware
Whr-G301N Firmware
Whr-Hp-G300N Firmware
Whr-Hp-Gn Firmware
Wpl-05G300 Firmware
Wzr-450Hp-Cwt Firmware
Wzr-450Hp-Ub Firmware
Wzr-Hp-Ag300H Firmware
Wzr-Hp-G300Nh Firmware
Wzr-Hp-G301Nh Firmware
Wzr-Hp-G302H Firmware
Wzr-Hp-G450H Firmware
Wzr-300Hp Firmware
Wzr-450Hp Firmware
Wzr-600Dhp Firmware
Wzr-D1100H Firmware

Affected Vendors

49
/ 100
moderate-risk
Severity 27/34 · High
Exploitability 1/34 · Minimal
Exposure 21/34 · High