First published: Thu Mar 31 2022(Updated: )
Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent authenticated attacker to bypass access restriction and to access the management screen of the product via unspecified vectors.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom Wrc-1167gst2 Firmware | <=1.25 | |
Elecom Wrc-1167gst2 Firmware | ||
Elecom Wrc-1167gst2a Firmware | <=1.25 | |
Elecom Wrc-1167gst2a Firmware | ||
Elecom Wrc-1167gst2h Firmware | <=1.25 | |
Elecom Wrc-1167gst2h Firmware | ||
Elecom Wrc-2533gs2-b Firmware | <=1.52 | |
Elecom Wrc-2533gs2-b Firmware | ||
Elecom WRC-2533GS2-W | <=1.52 | |
Elecom WRC-2533GS2-W | ||
Elecom Wrc-1750gs Firmware | <=1.03 | |
Elecom Wrc-1750gs Firmware | ||
Elecom Wrc-1750gsv | <=2.11 | |
Elecom Wrc-1750gsv Firmware | ||
Elecom Wrc-1900gst Firmware | <=1.03 | |
Elecom Wrc-1900gst Firmware | ||
Elecom Wrc-2533gst Firmware | <=1.03 | |
Elecom Wrc-2533gst Firmware | ||
Elecom Wrc-2533gst2-g Firmware | <=1.25 | |
Elecom Wrc-2533gst2-g | ||
Elecom Wrc-2533gsta Firmware | <=1.03 | |
Elecom Wrc-2533gsta Firmware | ||
Elecom Wrc-2533gst2sp Firmware | <=1.25 | |
Elecom Wrc-2533gst2sp Firmware | ||
Elecom Wrc-2533gst2-g Firmware | <=1.25 | |
Elecom Wrc-2533gst2-g Firmware | ||
Elecom Edwrc-2533gst2 | <=1.25 | |
Elecom Edwrc-2533gst2 Firmware | ||
Elecom Wrc-1167gs2-b | <=1.65 | |
Elecom Wrc-1167gs2-b Firmware | ||
Elecom WRC-1167GS2H-B | <=1.65 | |
Elecom Wrc-1167gs2h-b Firmware | ||
Elecom Wmc-dlgst2-w Firmware | <=1.24 | |
Elecom Wmc-dlgst2-w Firmware | ||
Elecom Wmc-m1267gst2-w Firmware | <=1.24 | |
Elecom Wmc-m1267gst2-w Firmware | ||
Elecom Wmc-2hc-w | <=1.24 | |
Elecom Wmc-2hc-w Firmware | ||
Elecom Wmc-c2533gst-w Firmware | <=1.24 | |
Elecom Wmc-c2533gst-w Firmware | ||
Elecom Wrc-1900gst2 Firmware | <=1.15 | |
Elecom Wrc-1900gst2 Firmware | ||
Elecom Wrc-1900gst2sp Firmware | <=1.15 | |
Elecom Wrc-1900gst2sp Firmware | ||
Elecom Wrc-1750gst2 Firmware | <=1.14 | |
Elecom Wrc-1750gst2 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the ELECOM LAN routers vulnerability is CVE-2022-25915.
The severity of CVE-2022-25915 is high (8.8).
The ELECOM LAN router firmware versions affected by the vulnerability are WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior.
To fix the ELECOM LAN routers vulnerability (CVE-2022-25915), update the firmware to a version higher than v1.25 for WRC-1167GST2, WRC-1167GST2A, and WRC-1167GST2H, and higher than v1.52 for WRC-2533GS2-B and WRC-2533GS2-W.
You can find more information about the ELECOM LAN routers vulnerability at the following references: [JVN](https://jvn.jp/en/jp/JVN88993473/) and [ELECOM website](https://www.elecom.co.jp/news/security/20211130-01/).