CVE Database
/

CVE-2024-21798

Back to search

CVE-2024-21798

Published: Feb 28, 2024

Modified: Nov 26, 2024

PUBLISHED

CVSS v3.0

4.8

MEDIUM

Description

ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Note that WMC-X1800GST-B is also included in e-Mesh Starter Kit "WMC-2LX-B".

VendorProductVersions

ELECOM CO.,LTD.

WRC-1167GS2-B

affected
v1.67 and earlier

ELECOM CO.,LTD.

WRC-1167GS2H-B

affected
v1.67 and earlier

ELECOM CO.,LTD.

WRC-1167GST2

affected
v1.32 and earlier

ELECOM CO.,LTD.

WRC-2533GS2-B

affected
v1.62 and earlier

ELECOM CO.,LTD.

WRC-2533GS2-W

affected
v1.62 and earlier

ELECOM CO.,LTD.

WRC-2533GS2V-B

affected
v1.62 and earlier

ELECOM CO.,LTD.

WRC-2533GST2

affected
v1.30 and earlier

ELECOM CO.,LTD.

WRC-X3200GST3-B

affected
v1.25 and earlier

ELECOM CO.,LTD.

WRC-G01-W

affected
v1.24 and earlier

ELECOM CO.,LTD.

WMC-X1800GST-B

affected
v1.41 and earlier

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

Required

Scope

Changed

Confidentiality

Low

Integrity

Low

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now