CVE-2021-20716

Hidden functionality in multiple Buffalo network devices (BHR-4RV firmware Ver.2.55 and prior, FS-G54 firmware Ver.2.04 and prior, WBR2-B11 firmware Ver.2.32 and prior, WBR2-G54 firmware Ver.2.32 and prior, WBR2-G54-KD firmware Ver.2.32 and prior, WBR-B11 firmware Ver.2.23 and prior, WBR-G54 firmware Ver.2.23 and prior, WBR-G54L firmware Ver.2.20 and prior, WHR2-A54G54 firmware Ver.2.25 and prior, WHR2-G54 firmware Ver.2.23 and prior, WHR2-G54V firmware Ver.2.55 and prior, WHR3-AG54 firmware Ver.2.23 and prior, WHR-G54 firmware Ver.2.16 and prior, WHR-G54-NF firmware Ver.2.10 and prior, WLA2-G54 firmware Ver.2.24 and prior, WLA2-G54C firmware Ver.2.24 and prior, WLA-B11 firmware Ver.2.20 and prior, WLA-G54 firmware Ver.2.20 and prior, WLA-G54C firmware Ver.2.20 and prior, WLAH-A54G54 firmware Ver.2.54 and prior, WLAH-AM54G54 firmware Ver.2.54 and prior, WLAH-G54 firmware Ver.2.54 and prior, WLI2-TX1-AG54 firmware Ver.2.53 and prior, WLI2-TX1-AMG54 firmware Ver.2.53 and prior, WLI2-TX1-G54 firmware Ver.2.20 and prior, WLI3-TX1-AMG54 firmware Ver.2.53 and prior, WLI3-TX1-G54 firmware Ver.2.53 and prior, WLI-T1-B11 firmware Ver.2.20 and prior, WLI-TX1-G54 firmware Ver.2.20 and prior, WVR-G54-NF firmware Ver.2.02 and prior, WZR-G108 firmware Ver.2.41 and prior, WZR-G54 firmware Ver.2.41 and prior, WZR-HP-G54 firmware Ver.2.41 and prior, WZR-RS-G54 firmware Ver.2.55 and prior, and WZR-RS-G54HP firmware Ver.2.55 and prior) allows a remote attacker to enable the debug option and to execute arbitrary code or OS commands, change the configuration, and cause a denial of service (DoS) condition.

Published: 2021-04-27 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2021-20716 is rated High Risk (69.6/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 3.18%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2021-20716

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 3.03% 3.18% +0.15%
2 2025-03-30 8.22% 3.03% -5.20%
3 2025-03-29 8.22%

Full EPSS history (18 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2021-20716

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
9.8 3.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Click to expand
Attack vector (AV:N)
Could be attacked over the internet or any normal routed network—not just someone sitting at the machine.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:U)
Damage stays in the same “trust bubble” as the broken component—no big spill into unrelated systems.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
3.9 5.9 [email protected]
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2021-20716

Affected software / configurations for CVE-2021-20716

Vendor Product Version Raw CPE
buffalo bhr-4rv_firmware <= 2.55 cpe:2.3:o:buffalo:bhr-4rv_firmware:*:*:*:*:*:*:*:*
buffalo fs-g54_firmware <= 2.04 cpe:2.3:o:buffalo:fs-g54_firmware:*:*:*:*:*:*:*:*
buffalo wbr2-b11_firmware <= 2.32 cpe:2.3:o:buffalo:wbr2-b11_firmware:*:*:*:*:*:*:*:*
buffalo wbr2-g54_firmware <= 2.32 cpe:2.3:o:buffalo:wbr2-g54_firmware:*:*:*:*:*:*:*:*
buffalo wbr2-g54-kd_firmware <= 2.32 cpe:2.3:o:buffalo:wbr2-g54-kd_firmware:*:*:*:*:*:*:*:*
buffalo wbr-b11_firmware <= 2.23 cpe:2.3:o:buffalo:wbr-b11_firmware:*:*:*:*:*:*:*:*
buffalo wbr-g54_firmware <= 2.23 cpe:2.3:o:buffalo:wbr-g54_firmware:*:*:*:*:*:*:*:*
buffalo wbr-g54l_firmware <= 2.20 cpe:2.3:o:buffalo:wbr-g54l_firmware:*:*:*:*:*:*:*:*
buffalo whr2-a54g54_firmware <= 2.25 cpe:2.3:o:buffalo:whr2-a54g54_firmware:*:*:*:*:*:*:*:*
buffalo whr2-g54_firmware <= 2.23 cpe:2.3:o:buffalo:whr2-g54_firmware:*:*:*:*:*:*:*:*
buffalo whr2-g54v_firmware <= 2.55 cpe:2.3:o:buffalo:whr2-g54v_firmware:*:*:*:*:*:*:*:*
buffalo whr3-ag54_firmware <= 2.23 cpe:2.3:o:buffalo:whr3-ag54_firmware:*:*:*:*:*:*:*:*
buffalo whr-g54_firmware <= 2.16 cpe:2.3:o:buffalo:whr-g54_firmware:*:*:*:*:*:*:*:*
buffalo whr-g54-nf_firmware <= 2.10 cpe:2.3:o:buffalo:whr-g54-nf_firmware:*:*:*:*:*:*:*:*
buffalo wla2-g54_firmware <= 2.24 cpe:2.3:o:buffalo:wla2-g54_firmware:*:*:*:*:*:*:*:*
buffalo wla2-g54c_firmware <= 2.24 cpe:2.3:o:buffalo:wla2-g54c_firmware:*:*:*:*:*:*:*:*
buffalo wla-b11_firmware <= 2.20 cpe:2.3:o:buffalo:wla-b11_firmware:*:*:*:*:*:*:*:*
buffalo wla-g54_firmware <= 2.20 cpe:2.3:o:buffalo:wla-g54_firmware:*:*:*:*:*:*:*:*
buffalo wla-g54c_firmware <= 2.20 cpe:2.3:o:buffalo:wla-g54c_firmware:*:*:*:*:*:*:*:*
buffalo wlah-a54g54_firmware <= 2.54 cpe:2.3:o:buffalo:wlah-a54g54_firmware:*:*:*:*:*:*:*:*
buffalo wlah-am54g54_firmware <= 2.54 cpe:2.3:o:buffalo:wlah-am54g54_firmware:*:*:*:*:*:*:*:*
buffalo wlah-g54_firmware <= 2.54 cpe:2.3:o:buffalo:wlah-g54_firmware:*:*:*:*:*:*:*:*
buffalo wli2-tx1-ag54_firmware <= 2.53 cpe:2.3:o:buffalo:wli2-tx1-ag54_firmware:*:*:*:*:*:*:*:*
buffalo wli2-tx1-amg54_firmware <= 2.53 cpe:2.3:o:buffalo:wli2-tx1-amg54_firmware:*:*:*:*:*:*:*:*
buffalo wli2-tx1-g54_firmware <= 2.20 cpe:2.3:o:buffalo:wli2-tx1-g54_firmware:*:*:*:*:*:*:*:*
buffalo wli3-tx1-amg54_firmware <= 2.53 cpe:2.3:o:buffalo:wli3-tx1-amg54_firmware:*:*:*:*:*:*:*:*
buffalo wli3-tx1-g54_firmware <= 2.53 cpe:2.3:o:buffalo:wli3-tx1-g54_firmware:*:*:*:*:*:*:*:*
buffalo wli-t1-b11_firmware <= 2.20 cpe:2.3:o:buffalo:wli-t1-b11_firmware:*:*:*:*:*:*:*:*
buffalo wli-tx1-g54_firmware <= 2.20 cpe:2.3:o:buffalo:wli-tx1-g54_firmware:*:*:*:*:*:*:*:*
buffalo wvr-g54-nf_firmware <= 2.02 cpe:2.3:o:buffalo:wvr-g54-nf_firmware:*:*:*:*:*:*:*:*
buffalo wzr-g108_firmware <= 2.41 cpe:2.3:o:buffalo:wzr-g108_firmware:*:*:*:*:*:*:*:*
buffalo wzr-g54_firmware <= 2.41 cpe:2.3:o:buffalo:wzr-g54_firmware:*:*:*:*:*:*:*:*
buffalo wzr-hp-g54_firmware <= 2.41 cpe:2.3:o:buffalo:wzr-hp-g54_firmware:*:*:*:*:*:*:*:*
buffalo wzr-rs-g54_firmware <= 2.55 cpe:2.3:o:buffalo:wzr-rs-g54_firmware:*:*:*:*:*:*:*:*
buffalo wzr-rs-g54hp_firmware <= 2.55 cpe:2.3:o:buffalo:wzr-rs-g54hp_firmware:*:*:*:*:*:*:*:*

References for CVE-2021-20716

cvelogic Threat Intelligence