First published: Wed Dec 01 2021(Updated: )
Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent unauthenticated attacker to bypass access restriction, and to start the telnet service and execute an arbitrary OS command via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom Wrc-1167gst2 Firmware | <=1.25 | |
Elecom Wrc-1167gst2 | ||
Elecom Wrc-1167gst2a Firmware | <=1.25 | |
Elecom Wrc-1167gst2a | ||
Elecom Wrc-1167gst2h Firmware | <=1.25 | |
Elecom Wrc-1167gst2h | ||
Elecom Wrc-2533gs2-b Firmware | <=1.52 | |
Elecom Wrc-2533gs2-b | ||
Elecom Wrc-2533gs2-w Firmware | <=1.52 | |
Elecom Wrc-2533gs2-w | ||
Elecom Wrc-1750gs Firmware | <=1.03 | |
Elecom Wrc-1750gs | ||
Elecom Wrc-1750gsv Firmware | <=2.11 | |
Elecom Wrc-1750gsv | ||
Elecom Wrc-1900gst Firmware | <=1.03 | |
Elecom Wrc-1900gst | ||
Elecom Wrc-2533gst Firmware | <=1.03 | |
Elecom Wrc-2533gst | ||
Elecom Wrc-2533gst2 Firmware | <=1.25 | |
Elecom Wrc-2533gst2 | ||
Elecom Wrc-2533gsta Firmware | <=1.03 | |
Elecom Wrc-2533gsta | ||
Elecom Wrc-2533gst2sp Firmware | <=1.25 | |
Elecom Wrc-2533gst2sp | ||
Elecom Wrc-2533gst2-g Firmware | <=1.25 | |
Elecom Wrc-2533gst2-g | ||
Elecom Edwrc-2533gst2 Firmware | <=1.25 | |
Elecom Edwrc-2533gst2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-20864.
The severity of CVE-2021-20864 is high with a severity value of 8.8.
ELECOM routers WRC-1167GST2, WRC-1167GST2A, WRC-1167GST2H, WRC-2533GS2-B, WRC-2533GS2-W, and WRC-1750GS with specific firmware versions are affected.
To fix CVE-2021-20864, it is recommended to update the firmware of the affected ELECOM routers to versions above 1.25 for WRC-1167GST2 models and above 1.52 for WRC-2533GS2-B and WRC-2533GS2-W models.
You can find more information about CVE-2021-20864 on the JVN website and the official ELECOM security advisory.