HIGH · 8.8

CVE-2023-39455

OS command injection vulnerability in ELECOM wireless LAN routers allows an authenticated user to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions...

Vulnerability Description

OS command injection vulnerability in ELECOM wireless LAN routers allows an authenticated user to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions are as follows: WRC-600GHBK-A all versions, WRC-1467GHBK-A all versions, WRC-1900GHBK-A all versions, WRC-733FEBK2-A all versions, WRC-F1167ACF2 all versions, WRC-1467GHBK-S all versions, and WRC-1900GHBK-S all versions.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
ElecomWrc-600Ghbk-A FirmwareAll versions
ElecomWrc-600Ghbk-A-
ElecomWrc-1467Ghbk-A FirmwareAll versions
ElecomWrc-1467Ghbk-A-
ElecomWrc-1900Ghbk-A FirmwareAll versions
ElecomWrc-1900Ghbk-A-
ElecomWrc-733Febk2-A FirmwareAll versions
ElecomWrc-733Febk2-A-
ElecomWrc-F1167Acf2 FirmwareAll versions
ElecomWrc-F1167Acf2-
ElecomWrc-1467Ghbk-S FirmwareAll versions
ElecomWrc-1467Ghbk-S-
ElecomWrc-1900Ghbk-S FirmwareAll versions
ElecomWrc-1900Ghbk-S-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-39455?

CVE-2023-39455 is a vulnerability with a CVSS score of 8.8 (HIGH). OS command injection vulnerability in ELECOM wireless LAN routers allows an authenticated user to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions...

How severe is CVE-2023-39455?

CVE-2023-39455 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-39455?

Check the references section above for vendor advisories and patch information. Affected products include: Elecom Wrc-600Ghbk-A Firmware, Elecom Wrc-600Ghbk-A, Elecom Wrc-1467Ghbk-A Firmware, Elecom Wrc-1467Ghbk-A, Elecom Wrc-1900Ghbk-A Firmware.