Vulnerability Description
ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and earlier allow a network-adjacent authenticated attacker to execute an arbitrary command by sending a specially crafted request to the web management page.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elecom | Wrc-1167Ghbk-S Firmware | <= 1.03 |
| Elecom | Wrc-1167Ghbk-S | - |
| Elecom | Wrc-1167Gebk-S Firmware | <= 1.03 |
| Elecom | Wrc-1167Gebk-S | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU91850798/Third Party Advisory
- https://www.elecom.co.jp/news/security/20230711-01/Vendor Advisory
- https://jvn.jp/en/vu/JVNVU91850798/Third Party Advisory
- https://www.elecom.co.jp/news/security/20230711-01/Vendor Advisory
FAQ
What is CVE-2023-37568?
CVE-2023-37568 is a vulnerability with a CVSS score of 8.0 (HIGH). ELECOM wireless LAN routers WRC-1167GHBK-S v1.03 and earlier, and WRC-1167GEBK-S v1.03 and earlier allow a network-adjacent authenticated attacker to execute an arbitrary command by sending a speciall...
How severe is CVE-2023-37568?
CVE-2023-37568 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-37568?
Check the references section above for vendor advisories and patch information. Affected products include: Elecom Wrc-1167Ghbk-S Firmware, Elecom Wrc-1167Ghbk-S, Elecom Wrc-1167Gebk-S Firmware, Elecom Wrc-1167Gebk-S.