CVE-2023-39454

Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:elecom:wrc-x1800gs-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1800gs-b:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:elecom:wrc-x1800gsa-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1800gsa-b:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:elecom:wrc-x1800gsh-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1800gsh-b:-:*:*:*:*:*:*:*

History

17 Feb 2025, 06:15

Type Values Removed Values Added
Summary (en) Buffer overflow vulnerability in WRC-X1800GS-B v1.13 and earlier, WRC-X1800GSA-B v1.13 and earlier, and WRC-X1800GSH-B v1.13 and earlier allows an unauthenticated attacker to execute arbitrary code. (en) Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code.

21 Nov 2024, 08:15

Type Values Removed Values Added
References () https://jvn.jp/en/vu/JVNVU91630351/ - Third Party Advisory () https://jvn.jp/en/vu/JVNVU91630351/ - Third Party Advisory
References () https://www.elecom.co.jp/news/security/20230711-01/ - Vendor Advisory () https://www.elecom.co.jp/news/security/20230711-01/ - Vendor Advisory

23 Aug 2023, 16:48

Type Values Removed Values Added
CPE cpe:2.3:o:elecom:wrc-x1800gsa-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-x1800gs-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1800gsh-b:-:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-x1800gsh-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1800gs-b:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1800gsa-b:-:*:*:*:*:*:*:*
CWE CWE-120
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
First Time Elecom wrc-x1800gsh-b
Elecom
Elecom wrc-x1800gs-b Firmware
Elecom wrc-x1800gsh-b Firmware
Elecom wrc-x1800gs-b
Elecom wrc-x1800gsa-b
Elecom wrc-x1800gsa-b Firmware
References (MISC) https://jvn.jp/en/vu/JVNVU91630351/ - (MISC) https://jvn.jp/en/vu/JVNVU91630351/ - Third Party Advisory
References (MISC) https://www.elecom.co.jp/news/security/20230711-01/ - (MISC) https://www.elecom.co.jp/news/security/20230711-01/ - Vendor Advisory

18 Aug 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-18 10:15

Updated : 2025-02-17 06:15


NVD link : CVE-2023-39454

Mitre link : CVE-2023-39454

CVE.ORG link : CVE-2023-39454


JSON object : View

Products Affected

elecom

  • wrc-x1800gs-b
  • wrc-x1800gsa-b
  • wrc-x1800gsh-b
  • wrc-x1800gsh-b_firmware
  • wrc-x1800gsa-b_firmware
  • wrc-x1800gs-b_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')