OS Command Injection Vulnerability in ELECOM Wireless LAN Routers
CVE-2023-37564
8HIGH
Summary
An OS command injection vulnerability exists in ELECOM wireless LAN routers, which permits an authenticated attacker within the network to execute arbitrary operating system commands with root privileges. This is accomplished by sending a specially crafted request to the devices, potentially leading to unauthorized control and manipulation of the router's functionalities. Affected models include WRC-1167GHBK-S v1.03 and earlier, WRC-1167GEBK-S v1.03 and earlier, WRC-1167FEBK-S v1.04 and earlier, WRC-1167GHBK3-A v1.24 and earlier, and WRC-1167FEBK-A v1.18 and earlier.
Affected Version(s)
WRC-1167FEBK-A v1.18 and earlier
WRC-1167FEBK-S v1.04 and earlier
WRC-1167GEBK-S v1.03 and earlier
References
CVSS V3.1
Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved