First published: Wed Jul 07 2021(Updated: )
WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all versions allows an unauthenticated network-adjacent attacker to execute an arbitrary OS command via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom Wrc-300febk Firmware | ||
Elecom Wrc-300febk | ||
Elecom Wrc-f300nf Firmware | ||
Elecom Wrc-f300nf | ||
Elecom Wrc-733febk Firmware | ||
Elecom Wrc-733febk | ||
Elecom Wrh-300rd Firmware | ||
Elecom Wrh-300rd | ||
Elecom Wrh-300bk Firmware | ||
Elecom Wrh-300bk | ||
Elecom Wrh-300sv Firmware | ||
Elecom Wrh-300sv | ||
Elecom Wrh-300wh Firmware | ||
Elecom Wrh-300wh | ||
Elecom Wrh-h300wh Firmware | ||
Elecom Wrh-h300wh | ||
Elecom Wrh-h300bk Firmware | ||
Elecom Wrh-h300bk | ||
Elecom Wrh-300bk-s Firmware | ||
Elecom Wrh-300bk-s | ||
Elecom Wrh-300wh-s Firmware | ||
Elecom Wrh-300wh-s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20739 is a vulnerability that allows an unauthenticated network-adjacent attacker to execute arbitrary OS commands.
WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S are affected by CVE-2021-20739.
CVE-2021-20739 has a severity rating of 8.8 (high).
An attacker can exploit CVE-2021-20739 by leveraging unspecified vectors to execute arbitrary OS commands.
You can find more information about CVE-2021-20739 at the following references: [JVNVU94260088](https://jvn.jp/en/vu/JVNVU94260088/index.html) and [Elecom Security Advisory](https://www.elecom.co.jp/news/security/20210706-01/).