CVE-2023-40069

OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions are as follows: WRC-F1167ACF all versions, WRC-1750GHBK all versions, WRC-1167GHBK2 all versions, WRC-1750GHBK2-I all versions, and WRC-1750GHBK-E all versions.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
elecomwrc-f1167acf_firmware
*
elecomwrc-1750ghbk_firmware
*
elecomwrc-1167ghbk2_firmware
*
elecomwrc-1750ghbk2-i_firmware
*
elecomwrc-1750ghbk-e_firmware
*
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
elecomwrc-f1167acf_firmware
𝑥
≤ *
ADP
elecomwrc-1750ghbk_firmware
𝑥
≤ *
ADP
elecomwrc-1167ghbk2_firmware
𝑥
≤ *
ADP
elecomwrc-1750ghbk2-i_firmware
𝑥
≤ *
ADP
elecomwrc-1750ghbk-e_firmware
𝑥
≤ *
ADP