First published: Thu Apr 04 2024(Updated: )
WRC-X3200GST3-B v1.25 and earlier, and WRC-G01-W v1.24 and earlier allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Elecom WRC-X3200GST3-B | <1.25 | |
Unknown WRC-G01-W | <1.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-29225 is considered a critical vulnerability due to its potential for exposing sensitive configuration information.
To fix CVE-2024-29225, upgrade the affected devices to the latest firmware versions of WRC-X3200GST3-B v1.26 and WRC-G01-W v1.25 or later.
CVE-2024-29225 affects the WRC-X3200GST3-B version 1.25 and earlier, and the WRC-G01-W version 1.24 and earlier.
Yes, CVE-2024-29225 can be exploited by a network-adjacent unauthenticated attacker.
CVE-2024-29225 allows an attacker to obtain sensitive configuration files containing potentially critical information.