Code injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute arbitrary code by sending a specially crafted request
Published Jul 13, 2023
8.0
HIGHCVSS 3.1
EPSS 0.53%
Description
Code injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute arbitrary code by sending a specially crafted request. Affected products and versions are as follows: WRC-1167GHBK-S v1.03 and earlier, WRC-1167GEBK-S v1.03 and earlier, WRC-1167FEBK-S v1.04 and earlier, WRC-1167GHBK3-A v1.24 and earlier, and WRC-1167FEBK-A v1.18 and earlier.
Affected products
-
- Version v1.18 and earlierStatusaffectedConstraints-
- Version
-
- Version v1.04 and earlierStatusaffectedConstraints-
- Version
-
- Version v1.03 and earlierStatusaffectedConstraints-
- Version
-
- Version v1.03 and earlierStatusaffectedConstraints-
- Version
-
- Version v1.24 and earlierStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Elecom Co.,ltd. | Wrc-1167febk-A | n/a |
| ||||||
| Elecom Co.,ltd. | Wrc-1167febk-S | n/a |
| ||||||
| Elecom Co.,ltd. | Wrc-1167gebk-S | n/a |
| ||||||
| Elecom Co.,ltd. | Wrc-1167ghbk-S | n/a |
| ||||||
| Elecom Co.,ltd. | Wrc-1167ghbk3-A | n/a |
|
Configuration 1
- ≤ 1.03
Running on/with
- n/a
Configuration 2
- ≤ 1.03
Running on/with
- n/a
Configuration 3
- ≤ 1.04
Running on/with
- n/a
Configuration 4
- ≤ 1.24
Running on/with
- n/a
Configuration 5
- ≤ 1.18
Running on/with
- n/a
-
- Version 0StatusaffectedConstraints<1.18
- Version
-
- Version 0StatusaffectedConstraints<1.04
- Version
-
- Version 0StatusaffectedConstraints<1.03
- Version
-
- Version 0StatusaffectedConstraints<1.03
- Version
-
- Version 0StatusaffectedConstraints<1.24
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Elecom | Wrc-1167febk-A | n/a |
| ||||||
| Elecom | Wrc-1167febk-S | n/a |
| ||||||
| Elecom | Wrc-1167gebk-S | n/a |
| ||||||
| Elecom | Wrc-1167ghbk-S | n/a |
| ||||||
| Elecom | Wrc-1167ghbk3-A | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-41451 Advisory
- https://jvn.jp/en/jp/JVN05223215/ Third Party Advisory
- https://www.elecom.co.jp/news/security/20230711-01/ Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-41451 | Advisory | |
| https://jvn.jp/en/jp/JVN05223215/ | Third Party Advisory | |
| https://www.elecom.co.jp/news/security/20230711-01/ | Vendor Advisory |
Change history (0)
No recorded changes yet.