CVE-2023-35991
Last modified
CVE-2023-35991 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. Affected products and versions are as follows: LAN-W300N/DR all versions, LAN-WH300N/DR all versions, LAN-W300N/P all versions, LAN-WH450N/GP all versions, LAN-WH300AN/DGP all versions, LAN-WH300N/DGP all versions, and LAN-WH300ANDGPE all versions.. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands. Affected products and versions are as follows: LAN-W300N/DR all versions, LAN-WH300N/DR all versions, LAN-W300N/P all versions, LAN-WH450N/GP all versions, LAN-WH300AN/DGP all versions, LAN-WH300N/DGP all versions, and LAN-WH300ANDGPE all versions.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Elecom | Lan-Wh300andgpe Firmware | All versions |
| Elecom | Lan-Wh300n\/Dgp Firmware | All versions |
| Elecom | Lan-Wh300an\/Dgp Firmware | All versions |
| Elecom | Lan-Wh450n\/Gp Firmware | All versions |
| Elecom | Lan-W300n\/P Firmware | All versions |
| Elecom | Lan-Wh300n\/Dr Firmware | All versions |
| Elecom | Lan-W300n\/Dr Firmware | All versions |
References
- https://jvn.jp/en/vu/JVNVU91630351/Third Party Advisory
- https://www.elecom.co.jp/news/security/20230810-01/Vendor Advisory
- https://jvn.jp/en/vu/JVNVU91630351/Third Party Advisory
- https://www.elecom.co.jp/news/security/20230810-01/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-35991?
How severe is CVE-2023-35991?
How do I fix CVE-2023-35991?
Are you affected by CVE-2023-35991?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
