Vulnerability Description
Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-300BK3-S firmware v1.05 and earlier, WRH-300DR3-S firmware v1.05 and earlier, WRH-300LB3-S firmware v1.05 and earlier, WRH-300PN3-S firmware v1.05 and earlier, WRH-300WH3-S firmware v1.05 and earlier, and WRH-300YG3-S firmware v1.05 and earlier) allows an attacker on the adjacent network to execute an arbitrary OS command via unspecified vectors.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elecom | Wrh-300Bk3 Firmware | <= 1.05 |
| Elecom | Wrh-300Bk3 | - |
| Elecom | Wrh-300Wh3 Firmware | <= 1.05 |
| Elecom | Wrh-300Wh3 | - |
| Elecom | Wrh-300Bk3-S Firmware | <= 1.05 |
| Elecom | Wrh-300Bk3-S | - |
| Elecom | Wrh-300Wh3-S Firmware | <= 1.05 |
| Elecom | Wrh-300Wh3-S | - |
| Elecom | Wrh-300Lb3-S Firmware | <= 1.05 |
| Elecom | Wrh-300Lb3-S | - |
| Elecom | Wrh-300Pn3-S Firmware | <= 1.05 |
| Elecom | Wrh-300Pn3-S | - |
| Elecom | Wrh-300Yg3-S Firmware | <= 1.05 |
| Elecom | Wrh-300Yg3-S | - |
| Elecom | Wrh-300Dr3-S Firmware | <= 1.05 |
| Elecom | Wrh-300Dr3-S | - |
References
- https://jvn.jp/en/jp/JVN17482543/index.htmlThird Party Advisory
- https://www.elecom.co.jp/news/security/20220208-02/Vendor Advisory
- https://jvn.jp/en/jp/JVN17482543/index.htmlThird Party Advisory
- https://www.elecom.co.jp/news/security/20220208-02/Vendor Advisory
FAQ
What is CVE-2022-21173?
CVE-2022-21173 is a vulnerability with a CVSS score of 8.8 (HIGH). Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-300BK3-S firmware v1.05 and earlier, WRH-300DR3-S firmware v...
How severe is CVE-2022-21173?
CVE-2022-21173 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-21173?
Check the references section above for vendor advisories and patch information. Affected products include: Elecom Wrh-300Bk3 Firmware, Elecom Wrh-300Bk3, Elecom Wrh-300Wh3 Firmware, Elecom Wrh-300Wh3, Elecom Wrh-300Bk3-S Firmware.