First published: Thu Jul 13 2023(Updated: )
ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and earlier allow a network-adjacent authenticated attacker to execute an arbitrary command by sending a specially crafted request to the web management page.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom Wrc-1167ghbk-s Firmware | <=1.03 | |
Elecom Wrc-1167ghbk-s | ||
Elecom Wrc-1167gebk-s Firmware | <=1.03 | |
Elecom Wrc-1167gebk-s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-37568 is high with a severity value of 8.
An attacker can exploit CVE-2023-37568 by sending a specially crafted request to the web management page of the affected ELECOM wireless LAN routers.
ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, as well as WRC-1167GEBK-S v1.03 and earlier, are affected by CVE-2023-37568.
To fix CVE-2023-37568, update the firmware of the ELECOM wireless LAN routers to a version higher than 1.03.
You can find more information about CVE-2023-37568 at the following references: [ELECOM Security News](https://www.elecom.co.jp/news/security/20230711-01/) and [JVN](https://jvn.jp/en/vu/JVNVU91850798/).