CVE-2023-43757

Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the affected products/versions, see the information provided by the vendor under [References] section.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.5 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
jpcertCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 13%
VendorProductVersion
elecomwrc-2533ghbk2-t_firmware
-
elecomwrc-2533ghbk-i_firmware
-
elecomwrc-1750ghbk2-i_firmware
-
elecomwrc-1750ghbk-e_firmware
-
elecomwrc-1750ghbk_firmware
-
elecomwrc-1167ghbk2_firmware
-
elecomwrc-1167ghbk_firmware
-
elecomwrc-f1167acf_firmware
-
elecomwrc-733ghbk_firmware
-
elecomwrc-733ghbk-i_firmware
-
elecomwrc-733ghbk-c_firmware
-
elecomwrc-300ghbk2-i_firmware
-
elecomwrc-300ghbk_firmware
-
elecomwrc-733febk_firmware
-
elecomwrc-300febk_firmware
-
elecomwrc-f300nf_firmware
-
elecomwrh-300wh-h_firmware
-
elecomwrh-300bk_firmware
-
elecomwrh-300wh_firmware
-
elecomwrh-300rd_firmware
-
elecomwrh-300sv_firmware
-
elecomwrh-300bk-s_firmware
-
elecomwrh-300wh-s_firmware
-
elecomwrh-300bk2-s_firmware
-
elecomwrh-300wh2-s_firmware
-
elecomwrh-h300bk_firmware
-
elecomwrh-h300wh_firmware
-
elecomwrh-150bk_firmware
-
elecomwrh-150wh_firmware
-
elecomlan-w300n\/rs_firmware
-
elecomlan-w301nr_firmware
-
elecomlan-w300n\/p_firmware
-
elecomlan-wh300n\/dgp_firmware
-
elecomlan-wh300ndgpe_firmware
-
𝑥
= Vulnerable software versions