First published: Thu Jul 13 2023(Updated: )
Cross-site request forgery (CSRF) vulnerability in exists in WTC-C1167GC-B v1.17 and earlier, and WTC-C1167GC-W v1.17 and earlier. If a user views a malicious page while logged in, unintended operations may be performed.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom Wtc-c1167gc-b Firmware | <=1.17 | |
Elecom Wtc-c1167gc-b | ||
Elecom Wtc-c1167gc-w Firmware | <=1.17 | |
Elecom Wtc-c1167gc-w |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this CSRF vulnerability is CVE-2023-37562.
The severity level of CVE-2023-37562 is high (8.8).
CVE-2023-37562 affects Elecom WTC-C1167GC-B firmware versions up to and including 1.17, and Elecom WTC-C1167GC-W firmware versions up to and including 1.17.
If a user views a malicious page while logged in, unintended operations may be performed.
It is recommended to update the firmware of Elecom WTC-C1167GC-B and WTC-C1167GC-W to a version higher than 1.17 to fix the CSRF vulnerability.