First published: Fri Aug 18 2023(Updated: )
Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom Lan-w300n\/rs Firmware | ||
Elecom Lan-w300n\/rs | ||
Elecom Lan-w300n\/pr5 Firmware | ||
Elecom Lan-w300n\/pr5 | ||
All of | ||
Elecom Lan-w300n\/rs Firmware | ||
Elecom Lan-w300n\/rs | ||
All of | ||
Elecom Lan-w300n\/pr5 Firmware | ||
Elecom Lan-w300n\/pr5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-32626 is a hidden functionality vulnerability in Elecom LAN-W300N/RS and LAN-W300N/PR5, allowing an unauthenticated attacker to log in to the product's management console and execute arbitrary OS commands.
CVE-2023-32626 has a severity rating of 9.8, which is classified as critical.
All versions of Elecom LAN-W300N/RS are affected by CVE-2023-32626.
All versions of Elecom LAN-W300N/PR5 are affected by CVE-2023-32626.
An unauthenticated attacker can exploit CVE-2023-32626 by logging in to the product's management console and executing arbitrary OS commands.
You can find more information about CVE-2023-32626 on the JVN website (https://jvn.jp/en/vu/JVNVU91630351/) and the Elecom website (https://www.elecom.co.jp/news/security/20230810-01/).