Vulnerability Description
Code injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute arbitrary code by sending a specially crafted request. Affected products and versions are as follows: WRC-1167GHBK-S v1.03 and earlier, WRC-1167GEBK-S v1.03 and earlier, WRC-1167FEBK-S v1.04 and earlier, WRC-1167GHBK3-A v1.24 and earlier, and WRC-1167FEBK-A v1.18 and earlier.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elecom | Wrc-1167Ghbk-S Firmware | <= 1.03 |
| Elecom | Wrc-1167Ghbk-S | - |
| Elecom | Wrc-1167Gebk-S Firmware | <= 1.03 |
| Elecom | Wrc-1167Gebk-S | - |
| Elecom | Wrc-1167Febk-S Firmware | <= 1.04 |
| Elecom | Wrc-1167Febk-S | - |
| Elecom | Wrc-1167Ghbk3-A Firmware | <= 1.24 |
| Elecom | Wrc-1167Ghbk3-A | - |
| Elecom | Wrc-1167Febk-A Firmware | <= 1.18 |
| Elecom | Wrc-1167Febk-A | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN05223215/Third Party Advisory
- https://www.elecom.co.jp/news/security/20230711-01/Vendor Advisory
- https://jvn.jp/en/jp/JVN05223215/Third Party Advisory
- https://www.elecom.co.jp/news/security/20230711-01/Vendor Advisory
FAQ
What is CVE-2023-37565?
CVE-2023-37565 is a vulnerability with a CVSS score of 8.0 (HIGH). Code injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute arbitrary code by sending a specially crafted request. Affected products and ver...
How severe is CVE-2023-37565?
CVE-2023-37565 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-37565?
Check the references section above for vendor advisories and patch information. Affected products include: Elecom Wrc-1167Ghbk-S Firmware, Elecom Wrc-1167Ghbk-S, Elecom Wrc-1167Gebk-S Firmware, Elecom Wrc-1167Gebk-S, Elecom Wrc-1167Febk-S Firmware.