CVE-2024-23910
EUVD-2024-2134028.02.2024, 23:15
Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators and to perform unintended operations to the affected product. Note that WMC-X1800GST-B and WSC-X1800GS-B are also included in e-Mesh Starter Kit "WMC-2LX-B".
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| elecom | wrc-1167gs2-b_firmware | 𝑥 < 1.73 |
| elecom | wrc-1167gs2h-b_firmware | 𝑥 < 1.73 |
| elecom | wrc-1167gst2_firmware | 𝑥 < 1.34 |
| elecom | wrc-2533gs2-b_firmware | 𝑥 < 1.68 |
| elecom | wrc-2533gs2-w_firmware | 𝑥 < 1.68 |
| elecom | wrc-2533gs2v-b_firmware | 𝑥 < 1.68 |
| elecom | wrc-2533gst2_firmware | 𝑥 < 1.31 |
| elecom | wrc-x3200gst3-b_firmware | 𝑥 < 1.27 |
| elecom | wrc-g01-w_firmware | 𝑥 < 1.26 |
| elecom | wmc-x1800gst-b_firmware | 𝑥 < 1.42 |
| elecom | wsc-x1800gs-b_firmware | 𝑥 < 1.42 |
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| elecom | wrc-1167gs2-b | 𝑥 < v1.67 | ADP |
| elecom | wrc-1167gs2h-b | 𝑥 < v1.67 | ADP |
| elecom | wrc-2533gs2-b | 𝑥 < v1.62 | ADP |
| elecom | wrc-2533gs2-w | 𝑥 < v1.62 | ADP |
| elecom | wrc-2533gs2v-b | 𝑥 < v1.62 | ADP |
| elecom | wrc-x3200gst3-b_firmware | elecom ≤ 𝑥 < v1.25 | ADP |
| elecom | wrc-g01-w_firmware | 𝑥 < v1.24 | ADP |
| elecom | wmc-x1800gst-b | 𝑥 < v1.41 | ADP |
| elecom | wsc-x1800gs-b | 𝑥 < v1.41 | ADP |
Common Weakness Enumeration