ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Note that WMC-X1800GST-B is also included in e-Mesh Starter Kit "WMC-2LX-B".
History

Fri, 14 Feb 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Elecom
Elecom wmc-x1800gst-b
Elecom wmc-x1800gst-b Firmware
Elecom wrc-1167gs2-b
Elecom wrc-1167gs2-b Firmware
Elecom wrc-1167gs2h-b
Elecom wrc-1167gs2h-b Firmware
Elecom wrc-1167gst2
Elecom wrc-1167gst2 Firmware
Elecom wrc-2533gs2-b
Elecom wrc-2533gs2-b Firmware
Elecom wrc-2533gs2-w
Elecom wrc-2533gs2-w Firmware
Elecom wrc-2533gs2v-b
Elecom wrc-2533gs2v-b Firmware
Elecom wrc-2533gst2
Elecom wrc-2533gst2 Firmware
Elecom wrc-g01-w
Elecom wrc-g01-w Firmware
Elecom wrc-x3200gst3-b
Elecom wrc-x3200gst3-b Firmware
CPEs cpe:2.3:h:elecom:wmc-x1800gst-b:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-1167gs2-b:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-1167gs2h-b:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-1167gst2:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-2533gs2-b:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-2533gs2-w:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-2533gs2v-b:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-2533gst2:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-g01-w:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x3200gst3-b:-:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wmc-x1800gst-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-1167gs2-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-1167gs2h-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-1167gst2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-2533gs2-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-2533gs2-w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-2533gs2v-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-2533gst2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-g01-w_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-x3200gst3-b_firmware:*:*:*:*:*:*:*:*
Vendors & Products Elecom
Elecom wmc-x1800gst-b
Elecom wmc-x1800gst-b Firmware
Elecom wrc-1167gs2-b
Elecom wrc-1167gs2-b Firmware
Elecom wrc-1167gs2h-b
Elecom wrc-1167gs2h-b Firmware
Elecom wrc-1167gst2
Elecom wrc-1167gst2 Firmware
Elecom wrc-2533gs2-b
Elecom wrc-2533gs2-b Firmware
Elecom wrc-2533gs2-w
Elecom wrc-2533gs2-w Firmware
Elecom wrc-2533gs2v-b
Elecom wrc-2533gs2v-b Firmware
Elecom wrc-2533gst2
Elecom wrc-2533gst2 Firmware
Elecom wrc-g01-w
Elecom wrc-g01-w Firmware
Elecom wrc-x3200gst3-b
Elecom wrc-x3200gst3-b Firmware
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Tue, 26 Nov 2024 08:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_0

{'score': 4.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}


Wed, 13 Nov 2024 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-11-26T08:07:04.819Z

Reserved: 2024-02-15T01:25:08.021Z

Link: CVE-2024-21798

cve-icon Vulnrichment

Updated: 2024-08-01T22:27:36.306Z

cve-icon NVD

Status : Analyzed

Published: 2024-02-28T23:15:09.453

Modified: 2025-02-14T15:32:23.757

Link: CVE-2024-21798

cve-icon Redhat

No data.