PT-2024-29127 · Elecom · Elecom Wrc-X6000Xs-G+1
Kentaro Ishii
·
Published
2024-08-01
·
Updated
2024-11-26
·
CVE-2024-40883
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ELECOM WRC-X6000XS-G/WRC-X1500GS-B/WRC-X1500GSA-B versions up to 1.11
Description
A cross-site request forgery issue exists in ELECOM wireless LAN routers. When a user with administrative privileges views a malicious page while logged in to the affected product, they may be directed to perform unintended operations, such as changing the login ID or login password.
Recommendations
For ELECOM WRC-X6000XS-G/WRC-X1500GS-B/WRC-X1500GSA-B versions up to 1.11, patch immediately to mitigate the risk of unauthorized actions on behalf of users.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Elecom Wrc-X1500Gsa-B
Elecom Wrc-X6000Xs-G