OS Command Injection Vulnerability in ELECOM Wireless LAN Routers
CVE-2023-37564

8HIGH

Key Information:

Vendor
CVE Published:
13 July 2023

Summary

An OS command injection vulnerability exists in ELECOM wireless LAN routers, which permits an authenticated attacker within the network to execute arbitrary operating system commands with root privileges. This is accomplished by sending a specially crafted request to the devices, potentially leading to unauthorized control and manipulation of the router's functionalities. Affected models include WRC-1167GHBK-S v1.03 and earlier, WRC-1167GEBK-S v1.03 and earlier, WRC-1167FEBK-S v1.04 and earlier, WRC-1167GHBK3-A v1.24 and earlier, and WRC-1167FEBK-A v1.18 and earlier.

Affected Version(s)

WRC-1167FEBK-A v1.18 and earlier

WRC-1167FEBK-S v1.04 and earlier

WRC-1167GEBK-S v1.03 and earlier

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.