ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and earlier allow a network-adjacent authenticated attacker to execute an arbitrary command by sending a specially crafted request to the web management page.
References
Link | Resource |
---|---|
https://jvn.jp/en/vu/JVNVU91850798/ | Third Party Advisory |
https://www.elecom.co.jp/news/security/20230711-01/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2023-07-13 02:15
Updated : 2023-07-25 14:10
NVD link : CVE-2023-37568
Mitre link : CVE-2023-37568
CVE.ORG link : CVE-2023-37568
JSON object : View
Products Affected
elecom
- wrc-1167gebk-s_firmware
- wrc-1167ghbk-s
- wrc-1167gebk-s
- wrc-1167ghbk-s_firmware
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')