Weak Encryption Vulnerability in ELECOM and LOGITEC Routers
CVE-2023-43757

6.5MEDIUM

Key Information:

Vendor
CVE Published:
16 November 2023

Summary

A vulnerability has been identified in multiple routers by ELECOM CO.,LTD. and LOGITEC CORPORATION, which allows an unauthenticated attacker on the same network to exploit weaknesses in the encryption mechanism. This issue enables potential attackers to guess the encryption key utilized for wireless LAN communications, leading to unauthorized interception of sensitive communications. Users of the affected routers should consult the vendor's advisory for more detailed guidance on securing their devices.

Affected Version(s)

LAN-W300N/P all versions

LAN-W300N/RS all versions

LAN-W301NR all versions

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.