SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-35991

Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands.

CRITICAL 9.8EPSS 0.72%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.72%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. Affected products and versions are as follows: LAN-W300N/DR all versions, LAN-WH300N/DR all versions, LAN-W300N/P all versions, LAN-WH450N/GP all versions, LAN-WH300AN/DGP all versions, LAN-WH300N/DGP all versions, and LAN-WH300ANDGPE all versions.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
0.72% probability · 52th percentile
CISA KEV
Not listed
Affected
elecom/lan-wh300andgpe firmware · elecom/lan-wh300n\/dgp firmware · elecom/lan-wh300an\/dgp firmware · elecom/lan-wh450n\/gp firmware · elecom/lan-w300n\/p firmware · elecom/lan-wh300n\/dr firmware · elecom/lan-w300n\/dr firmware
Source
vultures@jpcert.or.jp

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.