First published: Thu Jul 13 2023(Updated: )
ELECOM wireless LAN routers are vulnerable to sensitive information exposure, which allows a network-adjacent unauthorized attacker to obtain sensitive information. Affected products and versions are as follows: WRC-1167GHBK-S v1.03 and earlier, WRC-1167GEBK-S v1.03 and earlier, WRC-1167FEBK-S v1.04 and earlier, WRC-1167GHBK3-A v1.24 and earlier, WRC-1167FEBK-A v1.18 and earlier, WRC-F1167ACF2 all versions, WRC-600GHBK-A all versions, WRC-733FEBK2-A all versions, WRC-1467GHBK-A all versions, WRC-1467GHBK-S all versions, WRC-1900GHBK-A all versions, and WRC-1900GHBK-S all versions.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom Wrc-1167ghbk-s Firmware | <=1.03 | |
Elecom Wrc-1167ghbk-s | ||
Elecom Wrc-1167gebk-s Firmware | <=1.03 | |
Elecom Wrc-1167gebk-s | ||
Elecom Wrc-1167febk-s Firmware | <=1.04 | |
Elecom Wrc-1167febk-s | ||
Elecom Wrc-1167ghbk3-a Firmware | <=1.24 | |
Elecom Wrc-1167ghbk3-a | ||
Elecom Wrc-1167febk-a Firmware | <=1.18 | |
Elecom Wrc-1167febk-a | ||
All of | ||
Elecom Wrc-1167ghbk-s Firmware | <=1.03 | |
Elecom Wrc-1167ghbk-s | ||
All of | ||
Elecom Wrc-1167gebk-s | ||
Elecom Wrc-1167gebk-s Firmware | <=1.03 | |
All of | ||
Elecom Wrc-1167febk-s | ||
Elecom Wrc-1167febk-s Firmware | <=1.04 | |
All of | ||
Elecom Wrc-1167ghbk3-a | ||
Elecom Wrc-1167ghbk3-a Firmware | <=1.24 | |
All of | ||
Elecom Wrc-1167febk-a | ||
Elecom Wrc-1167febk-a Firmware | <=1.18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2023-37563.
The severity level of CVE-2023-37563 is medium.
An unauthorized attacker can exploit CVE-2023-37563 by obtaining sensitive information from the vulnerable ELECOM wireless LAN routers.
The affected products and versions for CVE-2023-37563 are as follows: ELECOM WRC-1167GHBK-S v1.03 and earlier, ELECOM WRC-1167GEBK-S v1.03 and earlier, ELECOM WRC-1167FEBK-S v1.04 and earlier, ELECOM WRC-1167GHBK3-A v1.24 and earlier, and ELECOM WRC-1167FEBK-A v1.18 and earlier.
You can find more information about CVE-2023-37563 on the following websites: [Elecom Security News](https://www.elecom.co.jp/news/security/20230711-01/), [JVN](https://jvn.jp/en/jp/JVN05223215/), and [Elecom Security News](https://www.elecom.co.jp/news/security/20230810-01/).