First published: Thu Nov 16 2023(Updated: )
OS command injection vulnerability in WRC-X3000GS2-W v1.05 and earlier, WRC-X3000GS2-B v1.05 and earlier, and WRC-X3000GS2A-B v1.05 and earlier allows a network-adjacent authenticated user to execute an arbitrary OS command by sending a specially crafted request.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Elecom Wrc-x3000gs2-w Firmware | <=1.05 | |
Elecom Wrc-x3000gs2-w | ||
All of | ||
Elecom Wrc-x3000gs2-b Firmware | <=1.05 | |
Elecom Wrc-x3000gs2-b | ||
All of | ||
Elecom Wrc-x3000gs2a-b Firmware | <=1.05 | |
Elecom Wrc-x3000gs2a-b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-43752 is an OS command injection vulnerability in WRC-X3000GS2-W v1.05 and earlier, WRC-X3000GS2-B v1.05 and earlier, and WRC-X3000GS2A-B v1.05 and earlier.
CVE-2023-43752 affects Elecom Wrc-x3000gs2-w firmware v1.05 and earlier by allowing a network-adjacent authenticated user to execute arbitrary OS commands.
CVE-2023-43752 affects Elecom Wrc-x3000gs2-b firmware v1.05 and earlier by allowing a network-adjacent authenticated user to execute arbitrary OS commands.
CVE-2023-43752 affects Elecom Wrc-x3000gs2a-b firmware v1.05 and earlier by allowing a network-adjacent authenticated user to execute arbitrary OS commands.
Here are the references for CVE-2023-43752: - [Elecom Security News](https://www.elecom.co.jp/news/security/20231114-01/) - [JVN](https://jvn.jp/en/vu/JVNVU94119876/)