HIGH · 8.8

CVE-2022-21173

Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-300BK3-S firmware v1.05 and earlier, WRH-300DR3-S firmware v...

Vulnerability Description

Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-300BK3-S firmware v1.05 and earlier, WRH-300DR3-S firmware v1.05 and earlier, WRH-300LB3-S firmware v1.05 and earlier, WRH-300PN3-S firmware v1.05 and earlier, WRH-300WH3-S firmware v1.05 and earlier, and WRH-300YG3-S firmware v1.05 and earlier) allows an attacker on the adjacent network to execute an arbitrary OS command via unspecified vectors.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ElecomWrh-300Bk3 Firmware<= 1.05
ElecomWrh-300Bk3-
ElecomWrh-300Wh3 Firmware<= 1.05
ElecomWrh-300Wh3-
ElecomWrh-300Bk3-S Firmware<= 1.05
ElecomWrh-300Bk3-S-
ElecomWrh-300Wh3-S Firmware<= 1.05
ElecomWrh-300Wh3-S-
ElecomWrh-300Lb3-S Firmware<= 1.05
ElecomWrh-300Lb3-S-
ElecomWrh-300Pn3-S Firmware<= 1.05
ElecomWrh-300Pn3-S-
ElecomWrh-300Yg3-S Firmware<= 1.05
ElecomWrh-300Yg3-S-
ElecomWrh-300Dr3-S Firmware<= 1.05
ElecomWrh-300Dr3-S-

References

FAQ

What is CVE-2022-21173?

CVE-2022-21173 is a vulnerability with a CVSS score of 8.8 (HIGH). Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-300BK3-S firmware v1.05 and earlier, WRH-300DR3-S firmware v...

How severe is CVE-2022-21173?

CVE-2022-21173 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-21173?

Check the references section above for vendor advisories and patch information. Affected products include: Elecom Wrh-300Bk3 Firmware, Elecom Wrh-300Bk3, Elecom Wrh-300Wh3 Firmware, Elecom Wrh-300Wh3, Elecom Wrh-300Bk3-S Firmware.