First published: Fri Aug 18 2023(Updated: )
OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions are as follows: WRC-F1167ACF all versions, WRC-1750GHBK all versions, WRC-1167GHBK2 all versions, WRC-1750GHBK2-I all versions, and WRC-1750GHBK-E all versions.
Credit: vultures@jpcert.or.jp vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom Wrc-f1167acf Firmware | ||
Elecom Wrc-f1167acf | ||
Elecom Wrc-1750ghbk Firmware | ||
Elecom Wrc-1750ghbk | ||
Elecom Wrc-1167ghbk2 Firmware | ||
Elecom Wrc-1167ghbk2 | ||
Elecom Wrc-1750ghbk2-i Firmware | ||
Elecom Wrc-1750ghbk2-i | ||
Elecom Wrc-1750ghbk-e Firmware | ||
Elecom Wrc-1750ghbk-e | ||
All of | ||
Elecom Wrc-f1167acf Firmware | ||
Elecom Wrc-f1167acf | ||
All of | ||
Elecom Wrc-1750ghbk Firmware | ||
Elecom Wrc-1750ghbk | ||
All of | ||
Elecom Wrc-1167ghbk2 Firmware | ||
Elecom Wrc-1167ghbk2 | ||
All of | ||
Elecom Wrc-1750ghbk2-i Firmware | ||
Elecom Wrc-1750ghbk2-i | ||
All of | ||
Elecom Wrc-1750ghbk-e Firmware | ||
Elecom Wrc-1750ghbk-e |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-40069 is an OS command injection vulnerability in ELECOM wireless LAN routers.
CVE-2023-40069 allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request.
The affected products and versions are ELECOM WRC-F1167ACF (all versions), WRC-1750GHBK (all versions), WRC-1167GHBK2 (all versions), WRC-1750GHBK2-i (all versions), and WRC-1750GHBK-e (all versions).
CVE-2023-40069 has a severity rating of 9.8 (Critical).
To fix CVE-2023-40069, update the firmware of the affected ELECOM wireless LAN routers to the latest version provided by the manufacturer.