First published: Tue Dec 12 2023(Updated: )
OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command by sending a specially crafted request to the product.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Elecom Wrc-x3000gsn Firmware | =1.0.2 | |
Elecom Wrc-x3000gsn | ||
All of | ||
Elecom Wrc-x3000gs Firmware | <=1.0.24 | |
Elecom Wrc-x3000gs | ||
All of | ||
Elecom Wrc-x3000gsa Firmware | <=1.0.24 | |
Elecom Wrc-x3000gsa |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49695 is categorized as a high severity vulnerability due to its potential to allow arbitrary OS command execution.
To remediate CVE-2023-49695, upgrade the firmware of the affected Elecom devices to the latest version available.
CVE-2023-49695 affects Elecom WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier.
CVE-2023-49695 is an OS command injection vulnerability that can be exploited by an attacker with administrative privileges.
CVE-2023-49695 requires network adjacency for exploitation, meaning it can be exploited by an attacker on the same network as the device.