Open Redirect Vulnerability in ELECOM Wireless LAN Routers and Repeaters
CVE-2023-37561

6.1MEDIUM

Key Information:

Vendor
CVE Published:
13 July 2023

Summary

An open redirect vulnerability exists in specific models of ELECOM wireless LAN routers and repeaters, allowing unauthorized remote attackers to redirect users to malicious sites. This vulnerability stems from improper validation of URLs, enabling phishing attacks through misleading links crafted by attackers. Users are urged to update their devices to patched versions to mitigate the risk associated with this security flaw.

Affected Version(s)

WRH-300WH-H v2.12 and earlier

WTC-300HWH v1.09 and earlier

WTC-C1167GC-B v1.17 and earlier

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.