First published: Fri Aug 18 2023(Updated: )
Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Elecom WRC-X1800GS-B | <=1.13 | |
Elecom WSC-X1800GS-B | ||
All of | ||
Elecom Wrc-x1800gsa-b | <=1.13 | |
Elecom WRC-X1800GS-B | ||
All of | ||
Elecom WRC-X1800GSH-B | <=1.13 | |
Elecom Wrc-x1800gsh-b Firmware | ||
Elecom WRC-X1800GS-B | <=1.13 | |
Elecom WSC-X1800GS-B | ||
Elecom Wrc-x1800gsa-b | <=1.13 | |
Elecom WRC-X1800GS-B | ||
Elecom WRC-X1800GSH-B | <=1.13 | |
Elecom Wrc-x1800gsh-b Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39454 is a buffer overflow vulnerability in WRC-X1800GS-B v1.13 and earlier, WRC-X1800GSA-B v1.13 and earlier, and WRC-X1800GSH-B v1.13 and earlier which allows an unauthenticated attacker to execute arbitrary code.
CVE-2023-39454 has a severity rating of 9.8, which is considered critical.
The following software versions are affected by CVE-2023-39454: WRC-X1800GS-B firmware up to and including v1.13, WRC-X1800GSA-B firmware up to and including v1.13, and WRC-X1800GSH-B firmware up to and including v1.13.
An unauthenticated attacker can exploit CVE-2023-39454 to execute arbitrary code.
Yes, you can find more information about CVE-2023-39454 at the following references: [Reference 1](https://jvn.jp/en/vu/JVNVU91630351/), [Reference 2](https://www.elecom.co.jp/news/security/20230711-01/)