Open Redirect Vulnerability in ELECOM Wireless LAN Routers and Repeaters
CVE-2023-37561
6.1MEDIUM
Summary
An open redirect vulnerability exists in specific models of ELECOM wireless LAN routers and repeaters, allowing unauthorized remote attackers to redirect users to malicious sites. This vulnerability stems from improper validation of URLs, enabling phishing attacks through misleading links crafted by attackers. Users are urged to update their devices to patched versions to mitigate the risk associated with this security flaw.
Affected Version(s)
WRH-300WH-H v2.12 and earlier
WTC-300HWH v1.09 and earlier
WTC-C1167GC-B v1.17 and earlier
References
CVSS V3.1
Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved