CVE-2023-49695

MEDIUM

ELECOM WRC-X3000GSN 1.0.2, WRC-X3000GS < 1.0.24, WRC-X3000GSA < 1.0.24 - Authenticated OS Command Injection

Title source: llm
STIX 2.1

Description

OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command by sending a specially crafted request to the product.

References (2)

Core 2

Scores

CVSS v3 6.8
EPSS 0.0086
EPSS Percentile 53.8%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-78
Status published
Products (3)
elecom/wrc-x3000gs_firmware < 1.0.24
elecom/wrc-x3000gsa_firmware < 1.0.24
elecom/wrc-x3000gsn_firmware 1.0.2
Published Dec 12, 2023
Tracked Since Feb 18, 2026