CVE-2024-25579

EUVD-2024-22907
OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to the product. Note that WMC-X1800GST-B is also included in e-Mesh Starter Kit "WMC-2LX-B".
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.8 MEDIUM
ADJACENT_NETWORK
LOW
HIGH
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 26%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
elecomwrc-1167gs2-b_firmware
𝑥
≤ 1.67
ADP
elecomwrc-1167gs2h-b_firmware
𝑥
≤ 1.67
ADP
elecomwrc-2533gs2-b_firmware
𝑥
≤ 1.62
ADP
elecomwrc-2533gs2-w_firmware
𝑥
≤ 1.62
ADP
elecomwrc-2533gs2v-b_firmware
𝑥
≤ 1.62
ADP
elecomwrc-x3200gst3-b_firmware
𝑥
≤ 1.25
ADP
elecomwrc-g01-w_firmware
𝑥
≤ 1.24
ADP
elecomwmc-x1800gst-b_firmware
𝑥
≤ 1.41
ADP
elecomwrc-1167gst2_firmware
𝑥
≤ 1.32
ADP
elecomwrc-2533gst2_firmware
𝑥
≤ 1.30
ADP