First published: Thu Jul 13 2023(Updated: )
Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a network-adjacent authenticated attacker to execute an arbitrary command by sending a specially crafted request to the web management page. Affected products and versions are as follows: WRC-1167GHBK3-A v1.24 and earlier, WRC-1167FEBK-A v1.18 and earlier, WRC-F1167ACF2 all versions, WRC-600GHBK-A all versions, WRC-733FEBK2-A all versions, WRC-1467GHBK-A all versions, WRC-1900GHBK-A all versions, and LAN-W301NR all versions.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom Wrc-1167ghbk3-a Firmware | <=1.24 | |
Elecom Wrc-1167ghbk3-a | ||
Elecom Wrc-1167febk-a Firmware | <=1.18 | |
Elecom Wrc-1167febk-a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37566 is a command injection vulnerability in ELECOM and LOGITEC wireless LAN routers that allows an authenticated attacker to execute arbitrary commands.
An attacker can exploit CVE-2023-37566 by sending a specially crafted request to the web management page of the affected routers.
The ELECOM wireless LAN routers affected by CVE-2023-37566 are WRC-1167GHBK3-A v1.24 and earlier, and WRC-1167FEBK-A v1.18 and earlier.
CVE-2023-37566 has a severity score of 8, indicating a high severity vulnerability.
Yes, firmware updates are available to fix the CVE-2023-37566 vulnerability. Please refer to the vendor's website for further information and instructions.