← Back

CVE-2024-40883

nvd nist
Published: Aug 1, 2024Modified: Nov 26, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging in to the affected product with an administrative privilege, the user may be directed to perform unintended operations such as changing the login ID, login password, etc.

Affected (6)

6 products
Wrc 2533gs2 B Firmware
Wrc 2533gs2 W Firmware
Wrc 2533gs2v B Firmware
Wrc X6000xs G Firmware
Wrc X1500gs B Firmware
Wrc X1500gsa B Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.69
Running on/withPlatform Versions
Elecom
Wrc 2533gs2 B
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.69
Running on/withPlatform Versions
Elecom
Wrc 2533gs2 W
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.69
Running on/withPlatform Versions
Elecom
Wrc 2533gs2v B
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.12
Running on/withPlatform Versions
Elecom
Wrc X6000xs G
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.12
Running on/withPlatform Versions
Elecom
Wrc X1500gs B
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 1.12
Running on/withPlatform Versions
Elecom
Wrc X1500gsa B
All versions

References (2)

Source: vultures@jpcert.or.jp
Third Party Advisory
Source: vultures@jpcert.or.jp
Vendor Advisory

Timeline

No history available yet.