ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Note that WMC-X1800GST-B is also included in e-Mesh Starter Kit "WMC-2LX-B".
References
Link | Resource |
---|---|
https://jvn.jp/en/jp/JVN44166658/ | Third Party Advisory |
https://www.elecom.co.jp/news/security/20240220-01/ | Vendor Advisory |
https://jvn.jp/en/jp/JVN44166658/ | Third Party Advisory |
https://www.elecom.co.jp/news/security/20240220-01/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Configuration 7 (hide)
AND |
|
Configuration 8 (hide)
AND |
|
Configuration 9 (hide)
AND |
|
Configuration 10 (hide)
AND |
|
History
14 Feb 2025, 15:32
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:h:elecom:wrc-2533gst2:-:*:*:*:*:*:*:* cpe:2.3:h:elecom:wrc-1167gs2h-b:-:*:*:*:*:*:*:* cpe:2.3:h:elecom:wrc-1167gs2-b:-:*:*:*:*:*:*:* cpe:2.3:h:elecom:wrc-x3200gst3-b:-:*:*:*:*:*:*:* cpe:2.3:h:elecom:wrc-g01-w:-:*:*:*:*:*:*:* cpe:2.3:h:elecom:wrc-2533gs2-w:-:*:*:*:*:*:*:* cpe:2.3:o:elecom:wrc-2533gs2-w_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:elecom:wmc-x1800gst-b:-:*:*:*:*:*:*:* cpe:2.3:o:elecom:wrc-2533gs2-b_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:elecom:wrc-2533gst2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:elecom:wrc-1167gst2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:elecom:wmc-x1800gst-b_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:elecom:wrc-1167gs2-b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:elecom:wrc-1167gst2:-:*:*:*:*:*:*:* cpe:2.3:o:elecom:wrc-g01-w_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:elecom:wrc-2533gs2v-b_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:elecom:wrc-x3200gst3-b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:elecom:wrc-2533gs2-b:-:*:*:*:*:*:*:* cpe:2.3:o:elecom:wrc-1167gs2h-b_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:elecom:wrc-2533gs2v-b:-:*:*:*:*:*:*:* |
|
References | () https://jvn.jp/en/jp/JVN44166658/ - Third Party Advisory | |
References | () https://www.elecom.co.jp/news/security/20240220-01/ - Vendor Advisory | |
First Time |
Elecom
Elecom wrc-1167gs2h-b Elecom wrc-1167gs2-b Elecom wrc-2533gs2v-b Firmware Elecom wrc-2533gs2-b Elecom wrc-2533gs2-b Firmware Elecom wrc-2533gst2 Firmware Elecom wrc-2533gst2 Elecom wmc-x1800gst-b Firmware Elecom wrc-g01-w Elecom wrc-2533gs2-w Elecom wrc-x3200gst3-b Firmware Elecom wrc-1167gst2 Elecom wmc-x1800gst-b Elecom wrc-g01-w Firmware Elecom wrc-1167gs2-b Firmware Elecom wrc-1167gst2 Firmware Elecom wrc-x3200gst3-b Elecom wrc-2533gs2-w Firmware Elecom wrc-1167gs2h-b Firmware Elecom wrc-2533gs2v-b |
26 Nov 2024, 09:15
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.8 |
CWE | CWE-79 |
21 Nov 2024, 08:55
Type | Values Removed | Values Added |
---|---|---|
References | () https://jvn.jp/en/jp/JVN44166658/ - | |
References | () https://www.elecom.co.jp/news/security/20240220-01/ - |
12 Jun 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Note that WMC-X1800GST-B is also included in e-Mesh Starter Kit "WMC-2LX-B". |
04 Apr 2024, 01:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
Summary | (en) ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Affected products and versions are as follows: WRC-1167GS2-B v1.67 and earlier, WRC-1167GS2H-B v1.67 and earlier, WRC-2533GS2-B v1.62 and earlier, WRC-2533GS2-W v1.62 and earlier, WRC-2533GS2V-B v1.62 and earlier, WRC-X3200GST3-B v1.25 and earlier, and WRC-G01-W v1.24 and earlier. |
28 Feb 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-28 23:15
Updated : 2025-02-14 15:32
NVD link : CVE-2024-21798
Mitre link : CVE-2024-21798
CVE.ORG link : CVE-2024-21798
JSON object : View
Products Affected
elecom
- wmc-x1800gst-b
- wrc-2533gs2v-b_firmware
- wrc-2533gs2v-b
- wrc-1167gst2_firmware
- wrc-2533gst2
- wrc-g01-w
- wrc-2533gs2-b
- wrc-x3200gst3-b_firmware
- wrc-x3200gst3-b
- wrc-1167gst2
- wrc-2533gs2-w_firmware
- wrc-1167gs2h-b_firmware
- wrc-2533gst2_firmware
- wmc-x1800gst-b_firmware
- wrc-g01-w_firmware
- wrc-2533gs2-w
- wrc-1167gs2-b_firmware
- wrc-1167gs2-b
- wrc-2533gs2-b_firmware
- wrc-1167gs2h-b
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')