LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-20090: Arcadyan Buffalo Firmware Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-20090 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability…

CVE-2021-20090 is a path traversal vulnerability in Arcadyan Buffalo firmware used in multiple routers across several vendors. Unauthenticated remote attackers can abuse it to bypass authentication and reach sensitive information on the device. For IT and security teams, this matters because consumer and small-business routers often sit at the network edge with weak segmentation, so a successful bypass can expose credentials, configuration data, or a foothold for further access.

Public detail is limited to the CISA description and the CWE-22 classification. Confirm exact product lists, fixed builds, and deployment guidance against the relevant vendor advisories before acting.

How it works

The weakness is CWE-22 (improper limitation of a pathname to a restricted directory). In this class of flaw, the device accepts attacker-controlled path elements (commonly sequences that traverse parent directories) without sufficient canonicalization or allow-list checks. When the web management or related service resolves those paths, the request can escape the intended document root or authenticated area.

According to the CISA summary, an unauthenticated remote attacker can use the path traversal to bypass authentication and access sensitive information. Typical abuse patterns for this class involve crafting HTTP requests that reference files or endpoints outside the normal authenticated scope. Exact request format, parameters, and reachable files are not provided in the given facts; treat any public proof-of-concept material as untrusted until validated against your own lab and the vendor advisory.

Am I affected? How to find it in your systems

Arcadyan Buffalo firmware appears in routers sold under multiple vendor brands. These devices commonly serve as home, branch, or small-office gateways, Wi-Fi access points, or ISP-supplied CPE. Inventory should cover both corporate-managed and BYOD/remote-worker equipment that may still be reachable from the internet or from less-trusted network segments.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the fixed firmware only from the device vendor’s official support channel, verify integrity if hashes or signatures are published, and follow the vendor’s install and reboot procedure. After upgrading, re-check that the management interface version string matches the remediated build.

If you can't patch immediately

Reduce exposure until the vendor update can be applied.

If your data may have been exposed

Actively exploited edge vulnerabilities can lead to credential theft, configuration disclosure, or broader network compromise even when ransomware use is not documented for this CVE. If logs or telemetry suggest exploitation, treat the device as untrusted: isolate it, preserve evidence, rotate secrets that traversed the device, and hunt for lateral movement from the LAN side.

You can also run a free exposure scan of your email addresses against known breach data to see whether associated credentials have appeared in prior incidents, then force password resets and enable multi-factor authentication where possible.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedArcadyan · Buffalo Firmware
WeaknessCWE-22
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities