CVE-2024-21798

ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Note that WMC-X1800GST-B is also included in e-Mesh Starter Kit "WMC-2LX-B".
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:elecom:wrc-1167gs2-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-1167gs2-b:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:elecom:wrc-1167gs2h-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-1167gs2h-b:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:elecom:wrc-1167gst2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-1167gst2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:elecom:wrc-2533gs2-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-2533gs2-b:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:elecom:wrc-2533gs2-w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-2533gs2-w:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:elecom:wrc-2533gs2v-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-2533gs2v-b:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:elecom:wrc-2533gst2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-2533gst2:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:elecom:wrc-x3200gst3-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x3200gst3-b:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:elecom:wrc-g01-w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-g01-w:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:elecom:wmc-x1800gst-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wmc-x1800gst-b:-:*:*:*:*:*:*:*

History

14 Feb 2025, 15:32

Type Values Removed Values Added
CPE cpe:2.3:h:elecom:wrc-2533gst2:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-1167gs2h-b:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-1167gs2-b:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x3200gst3-b:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-g01-w:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-2533gs2-w:-:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-2533gs2-w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wmc-x1800gst-b:-:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-2533gs2-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-2533gst2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-1167gst2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wmc-x1800gst-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-1167gs2-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-1167gst2:-:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-g01-w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-2533gs2v-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-x3200gst3-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-2533gs2-b:-:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-1167gs2h-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-2533gs2v-b:-:*:*:*:*:*:*:*
References () https://jvn.jp/en/jp/JVN44166658/ - () https://jvn.jp/en/jp/JVN44166658/ - Third Party Advisory
References () https://www.elecom.co.jp/news/security/20240220-01/ - () https://www.elecom.co.jp/news/security/20240220-01/ - Vendor Advisory
First Time Elecom
Elecom wrc-1167gs2h-b
Elecom wrc-1167gs2-b
Elecom wrc-2533gs2v-b Firmware
Elecom wrc-2533gs2-b
Elecom wrc-2533gs2-b Firmware
Elecom wrc-2533gst2 Firmware
Elecom wrc-2533gst2
Elecom wmc-x1800gst-b Firmware
Elecom wrc-g01-w
Elecom wrc-2533gs2-w
Elecom wrc-x3200gst3-b Firmware
Elecom wrc-1167gst2
Elecom wmc-x1800gst-b
Elecom wrc-g01-w Firmware
Elecom wrc-1167gs2-b Firmware
Elecom wrc-1167gst2 Firmware
Elecom wrc-x3200gst3-b
Elecom wrc-2533gs2-w Firmware
Elecom wrc-1167gs2h-b Firmware
Elecom wrc-2533gs2v-b

26 Nov 2024, 09:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.8
CWE CWE-79

21 Nov 2024, 08:55

Type Values Removed Values Added
References () https://jvn.jp/en/jp/JVN44166658/ - () https://jvn.jp/en/jp/JVN44166658/ -
References () https://www.elecom.co.jp/news/security/20240220-01/ - () https://www.elecom.co.jp/news/security/20240220-01/ -

12 Jun 2024, 01:15

Type Values Removed Values Added
Summary (en) ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Affected products and versions are as follows: WRC-1167GS2-B v1.67 and earlier, WRC-1167GS2H-B v1.67 and earlier, WRC-2533GS2-B v1.62 and earlier, WRC-2533GS2-W v1.62 and earlier, WRC-2533GS2V-B v1.62 and earlier, WRC-X3200GST3-B v1.25 and earlier, and WRC-G01-W v1.24 and earlier. (en) ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Note that WMC-X1800GST-B is also included in e-Mesh Starter Kit "WMC-2LX-B".

04 Apr 2024, 01:15

Type Values Removed Values Added
Summary
  • (es) Los enrutadores de LAN inalámbrica ELECOM contienen una vulnerabilidad de cross-site scripting. Supongamos que un usuario administrativo malintencionado configura el producto afectado con contenido especialmente manipulado. Cuando otro usuario administrativo inicia sesión y opera el producto, se puede ejecutar un script arbitrario en el navegador web. Los productos y versiones afectados son los siguientes: WRC-1167GS2-B v1.67 y anteriores, WRC-1167GS2H-B v1.67 y anteriores, WRC-2533GS2-B v1.62 y anteriores, WRC-2533GS2-W v1.62 y anteriores y WRC-2533GS2V-B v1.62 y anteriores.
Summary (en) ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Affected products and versions are as follows: WRC-1167GS2-B v1.67 and earlier, WRC-1167GS2H-B v1.67 and earlier, WRC-2533GS2-B v1.62 and earlier, WRC-2533GS2-W v1.62 and earlier, and WRC-2533GS2V-B v1.62 and earlier. (en) ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Affected products and versions are as follows: WRC-1167GS2-B v1.67 and earlier, WRC-1167GS2H-B v1.67 and earlier, WRC-2533GS2-B v1.62 and earlier, WRC-2533GS2-W v1.62 and earlier, WRC-2533GS2V-B v1.62 and earlier, WRC-X3200GST3-B v1.25 and earlier, and WRC-G01-W v1.24 and earlier.

28 Feb 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-28 23:15

Updated : 2025-02-14 15:32


NVD link : CVE-2024-21798

Mitre link : CVE-2024-21798

CVE.ORG link : CVE-2024-21798


JSON object : View

Products Affected

elecom

  • wmc-x1800gst-b
  • wrc-2533gs2v-b_firmware
  • wrc-2533gs2v-b
  • wrc-1167gst2_firmware
  • wrc-2533gst2
  • wrc-g01-w
  • wrc-2533gs2-b
  • wrc-x3200gst3-b_firmware
  • wrc-x3200gst3-b
  • wrc-1167gst2
  • wrc-2533gs2-w_firmware
  • wrc-1167gs2h-b_firmware
  • wrc-2533gst2_firmware
  • wmc-x1800gst-b_firmware
  • wrc-g01-w_firmware
  • wrc-2533gs2-w
  • wrc-1167gs2-b_firmware
  • wrc-1167gs2-b
  • wrc-2533gs2-b_firmware
  • wrc-1167gs2h-b
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')