OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OS commands by sending a specially crafted request to the product.
Metrics
Affected Vendors & Products
References
History
Tue, 26 Nov 2024 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Elecom
Elecom wrc-g01-w Firmware Elecom wrc-x3200gst3-b Firmware |
|
CPEs | cpe:2.3:o:elecom:wrc-g01-w_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:elecom:wrc-x3200gst3-b_firmware:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Elecom
Elecom wrc-g01-w Firmware Elecom wrc-x3200gst3-b Firmware |
|
Metrics |
cvssV3_0
|
Mon, 09 Sep 2024 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | OS command injection vulnerability in WRC-X3200GST3-B v1.25 and earlier, and WRC-G01-W v1.24 and earlier allows a network-adjacent attacker with credentials to execute arbitrary OS commands by sending a specially crafted request to the product. | OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OS commands by sending a specially crafted request to the product. |
MITRE
Status: PUBLISHED
Assigner: jpcert
Published: 2024-04-04T00:03:41.930Z
Updated: 2024-11-26T08:00:41.733Z
Reserved: 2024-03-19T02:32:14.173Z
Link: CVE-2024-26258
Vulnrichment
Updated: 2024-08-02T00:07:19.139Z
NVD
Status : Awaiting Analysis
Published: 2024-04-04T00:15:07.047
Modified: 2024-11-26T08:15:04.673
Link: CVE-2024-26258
Redhat
No data.