CVE-2023-39454

Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:elecom:wrc-x1800gs-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1800gs-b:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:elecom:wrc-x1800gsa-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1800gsa-b:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:elecom:wrc-x1800gsh-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1800gsh-b:-:*:*:*:*:*:*:*

History

17 Feb 2025, 06:15

Type Values Removed Values Added
Summary Buffer overflow vulnerability in WRC-X1800GS-B v1.13 and earlier, WRC-X1800GSA-B v1.13 and earlier, and WRC-X1800GSH-B v1.13 and earlier allows an unauthenticated attacker to execute arbitrary code. Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code.
References (MISC) https://www.elecom.co.jp/news/security/20230711-01/ - Vendor Advisory () https://www.elecom.co.jp/news/security/20230711-01/ - Vendor Advisory
References (MISC) https://jvn.jp/en/vu/JVNVU91630351/ - Third Party Advisory () https://jvn.jp/en/vu/JVNVU91630351/ - Third Party Advisory

23 Aug 2023, 16:48

Type Values Removed Values Added
References (MISC) https://www.elecom.co.jp/news/security/20230711-01/ - (MISC) https://www.elecom.co.jp/news/security/20230711-01/ - Vendor Advisory
References (MISC) https://jvn.jp/en/vu/JVNVU91630351/ - (MISC) https://jvn.jp/en/vu/JVNVU91630351/ - Third Party Advisory
First Time Elecom wrc-x1800gsh-b Firmware
Elecom wrc-x1800gs-b Firmware
Elecom wrc-x1800gs-b
Elecom
Elecom wrc-x1800gsa-b
Elecom wrc-x1800gsa-b Firmware
Elecom wrc-x1800gsh-b
CWE CWE-120
CPE cpe:2.3:h:elecom:wrc-x1800gs-b:-:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-x1800gsa-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1800gsa-b:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1800gsh-b:-:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-x1800gsh-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-x1800gs-b_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

18 Aug 2023, 10:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-08-18 10:15

Updated : 2025-02-17 06:15


NVD link : CVE-2023-39454

Mitre link : CVE-2023-39454


JSON object : View

Products Affected

elecom

  • wrc-x1800gsh-b_firmware
  • wrc-x1800gsh-b
  • wrc-x1800gs-b_firmware
  • wrc-x1800gs-b
  • wrc-x1800gsa-b
  • wrc-x1800gsa-b_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')