ZeroHour

CVE-2024-23910

CVSS 3.1
8.8 high
EPSS
<1%p16
Published
()
Modified
Description

Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators and to perform unintended operations to the affected product. Note that WMC-X1800GST-B and WSC-X1800GS-B are also included in e-Mesh Starter Kit "WMC-2LX-B".

Vendors
elecom
Products
wrc-1167gs2-b firmware, wrc-1167gs2h-b firmware, wrc-1167gst2 firmware, wrc-2533gs2-b firmware, wrc-2533gs2-w firmware, wrc-2533gs2v-b firmware, wrc-2533gst2 firmware, wrc-x3200gst3-b firmware, wrc-g01-w firmware, wmc-x1800gst-b firmware, wsc-x1800gs-b firmware
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.