Executive brief
Multiple ELECOM wireless LAN routers are affected by a security flaw that allows an attacker on the same local network to download the device's configuration file. This file often contains sensitive information such as network settings and credentials. An attacker could use this data to gain further access to the network or compromise the router's security.
Technical details
The vulnerability is classified as an exposure of sensitive information (CWE-552/CWE-200) within the web management interface of several ELECOM router models. An unauthenticated attacker located on the same local network (adjacent) can bypass intended access controls by sending a specially crafted HTTP request to the device. This request triggers the unauthorized download of the router's configuration file. Successful exploitation allows the attacker to read sensitive configuration parameters, which may include administrative credentials or network secrets. Firmware updates have been released to address this issue.
Affected products
- ELECOM WRC-X3200GST3-B v1.25 and earlier
- ELECOM WRC-G01-W v1.24 and earlier
- ELECOM WMC-2LX-B v1.42 and earlier
- ELECOM WMC-X1800GST-B v1.42 and earlier
- ELECOM WSC-X1800GS-B v1.42 and earlier
Timeline
- 2024-03-26: advisory: Initial advisory published by JVN/JPCERT
- 2024-04-04: disclosed: CVE published to NVD