OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute an arbitrary OS command with a root privilege by sending a specially crafted request. Affected products and versions are as follows: WRC-1167GHBK-S v1.03 and earlier, WRC-1167GEBK-S v1.03 and earlier, WRC-1167FEBK-S v1.04 and earlier, WRC-1167GHBK3-A v1.24 and earlier, and WRC-1167FEBK-A v1.18 and earlier.
References
Link | Resource |
---|---|
https://jvn.jp/en/jp/JVN05223215/ | Third Party Advisory |
https://www.elecom.co.jp/news/security/20230711-01/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jpcert
Published: 2023-07-13T03:01:41.200Z
Updated: 2023-07-13T03:01:41.200Z
Reserved: 2023-07-07T08:46:11.998Z
Link: CVE-2023-37564
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-07-13T04:15:10.213
Modified: 2023-07-25T14:49:22.723
Link: CVE-2023-37564
JSON object: View
Redhat Information
No data.
CWE