First published: Wed Feb 28 2024(Updated: )
OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to the product. Note that WMC-X1800GST-B is also included in e-Mesh Starter Kit "WMC-2LX-B".
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom Wmc-x1800gst-b Firmware | ||
ELECOM e-Mesh Starter Kit WMC-2LX-B |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-25579 is classified as a high-severity OS command injection vulnerability.
To remediate CVE-2024-25579, update the firmware of affected ELECOM wireless LAN routers to the latest version provided by the vendor.
CVE-2024-25579 impacts users of the ELECOM WMC-X1800GST-B and the e-Mesh Starter Kit WMC-2LX-B.
An attacker must have network adjacency and administrative privileges to exploit CVE-2024-25579.
CVE-2024-25579 allows the execution of arbitrary OS commands by sending a specially crafted request.