November 3, 2021 · Applied Cybernetics Group
CVE-2021-20090 — Arcadyan Buffalo Firmware
Arcadyan Buffalo Firmware Path Traversal Vulnerability
- Added to KEV
2021-11-03- Federal due date
2021-11-17- Vendor
- Arcadyan
- Product
- Buffalo Firmware
- EPSS
- 100.0th percentile (score 0.944, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-20090
CISA short description
Arcadyan Buffalo firmware contains a path traversal vulnerability that could allow unauthenticated, remote attackers to bypass authentication and access sensitive information. This vulnerability affects multiple routers across several different vendors.
Required action
Apply updates per vendor instructions.