CVE-2023-37568

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
13/07/2023
Last modified:
25/07/2023

Description

ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and earlier allow a network-adjacent authenticated attacker to execute an arbitrary command by sending a specially crafted request to the web management page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:elecom:wrc-1167ghbk-s_firmware:*:*:*:*:*:*:*:* 1.03 (including)
cpe:2.3:h:elecom:wrc-1167ghbk-s:-:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-1167gebk-s_firmware:*:*:*:*:*:*:*:* 1.03 (including)
cpe:2.3:h:elecom:wrc-1167gebk-s:-:*:*:*:*:*:*:*