CVE-2023-37567
moderate-risk
Published 2023-07-13
Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary command by sending a specially crafted request to a certain port of the web management page. Affected products and versions are as follows: WRC-1167GHBK3-A v1.24 and earlier, WRC-F1167ACF2 all versions, WRC-600GHBK-A all versions, WRC-733FEBK2-A all versions, WRC-1467GHBK-A all versions, WRC-1900GHBK-A all versions, and LAN-W301NR all versions.
Do I need to act?
~
3.7% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.8/10
Critical
NETWORK
/ LOW complexity
Affected Products (1)
Wrc-1167Ghbk3-A Firmware
Affected Vendors
References (6)
Third Party Advisory
https://jvn.jp/en/vu/JVNVU91850798/
Vendor Advisory
https://www.elecom.co.jp/news/security/20230711-01/
Third Party Advisory
https://jvn.jp/en/vu/JVNVU91850798/
Vendor Advisory
https://www.elecom.co.jp/news/security/20230711-01/
44
/ 100
moderate-risk
Severity
32/34 · Critical
Exploitability
7/34 · Low
Exposure
5/34 · Minimal