CVE-2024-23910
Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators and to perform unintended operations to the affected product.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.25%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators and to perform unintended operations to the affected product. Note that WMC-X1800GST-B and WSC-X1800GS-B are also included in e-Mesh Starter Kit "WMC-2LX-B".
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- elecom/wrc-1167gs2-b firmware · elecom/wrc-1167gs2h-b firmware · elecom/wrc-1167gst2 firmware · elecom/wrc-2533gs2-b firmware · elecom/wrc-2533gs2-w firmware · elecom/wrc-2533gs2v-b firmware · elecom/wrc-2533gst2 firmware · elecom/wrc-x3200gst3-b firmware · elecom/wrc-g01-w firmware · elecom/wmc-x1800gst-b firmware · elecom/wsc-x1800gs-b firmware
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/jp/JVN44166658/Third Party Advisory
- https://www.elecom.co.jp/news/security/20240220-01/Vendor Advisory
- https://jvn.jp/en/jp/JVN44166658/Third Party Advisory
- https://www.elecom.co.jp/news/security/20240220-01/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.