First published: Thu Jul 13 2023(Updated: )
Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port of the web management page. Affected products and versions are as follows: WRC-1167GHBK3-A v1.24 and earlier, WRC-F1167ACF2 all versions, WRC-600GHBK-A all versions, WRC-733FEBK2-A all versions, WRC-1467GHBK-A all versions, WRC-1900GHBK-A all versions, and LAN-W301NR all versions.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom Wrc-1167ghbk3-a Firmware | <=1.24 | |
Elecom Wrc-1167ghbk3-a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37567 is a command injection vulnerability in ELECOM wireless LAN router WRC-1167GHBK3-A v1.24 and earlier.
CVE-2023-37567 allows a remote unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port of the web management page.
CVE-2023-37567 has a severity rating of 9.8 (critical).
The affected product is ELECOM wireless LAN router WRC-1167GHBK3-A v1.24 and earlier.
To fix CVE-2023-37567, update the firmware of the ELECOM wireless LAN router WRC-1167GHBK3-A to version 1.25 or later.