OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to the product. Affected products and versions are as follows: WRC-X1800GS-B v1.17 and earlier, WRC-X1800GSA-B v1.17 and earlier, WRC-X1800GSH-B v1.17 and earlier, WRC-X6000XS-G v1.09, and WRC-X6000XST-G v1.12 and earlier.
References
Link | Resource |
---|---|
https://jvn.jp/en/vu/JVNVU90908488/ | Third Party Advisory |
https://www.elecom.co.jp/news/security/20240123-01/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jpcert
Published: 2024-01-24T04:38:20.199Z
Updated: 2024-01-24T04:38:20.199Z
Reserved: 2024-01-10T00:47:14.234Z
Link: CVE-2024-22372
JSON object: View
NVD Information
Status : Analyzed
Published: 2024-01-24T05:15:14.137
Modified: 2024-01-30T22:17:49.987
Link: CVE-2024-22372
JSON object: View
Redhat Information
No data.
CWE