OS Command Injection Vulnerability in ELECOM Wireless LAN Routers
CVE-2023-40069

9.8CRITICAL

Key Information:

Vendor
CVE Published:
18 August 2023

Summary

An OS command injection vulnerability has been identified in ELECOM wireless LAN routers, enabling unauthorized access to execute arbitrary operating system commands. This risk arises when attackers send specifically crafted requests to the affected devices, which may lead to severe security breaches. The vulnerability impacts several models including WRC-F1167ACF, WRC-1750GHBK, WRC-1167GHBK2, WRC-1750GHBK2-I, and WRC-1750GHBK-E across all versions. Users are advised to review their network security measures and apply necessary updates.

Affected Version(s)

WRC-1167GHBK2 all versions

WRC-1750GHBK all versions

WRC-1750GHBK-E all versions

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.