Stored Cross-Site Scripting Vulnerability in Elecom WRC-1167GHBK2-S
CVE-2025-43877
4.8MEDIUM
What is CVE-2025-43877?
The Elecom WRC-1167GHBK2-S router is susceptible to a stored cross-site scripting vulnerability within its WebGUI. This flaw allows an attacker to inject arbitrary scripts that execute in the web browser of a user accessing the WebGUI. If successfully exploited, this could lead to unauthorized actions being performed on behalf of the victim, potentially exposing sensitive information or compromising user security.
Affected Version(s)
WRC-1167GHBK2-S all versions
References
CVSS V4
Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
CVSS V3.0
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved