Executive brief
Elecom wireless LAN routers are affected by a security flaw that could allow an attacker to execute malicious scripts in a user's web browser. This occurs if a logged-in administrator visits a specially crafted website while their router management session is active. An exploit could lead to unauthorized changes to router settings or the theft of session information, potentially compromising the security of the local network.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in multiple Elecom router models (WRC-X3000 series) due to improper neutralization of input values within the 'easysetup.cgi' script. The vulnerability is triggered when the application fails to properly sanitize user-supplied data before including it in the web response. An unauthenticated remote attacker can exploit this by enticing an authenticated user to visit a malicious URL or web page. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser, which can be used to hijack administrative sessions or modify device configurations. Firmware updates have been released to address this issue.
Affected products
- Elecom WRC-X3000GS2-B v1.08 and earlier
- Elecom WRC-X3000GS2-W v1.08 and earlier
- Elecom WRC-X3000GS2A-B v1.08 and earlier
- Elecom WRC-X3000GST2-B v1.06 and earlier
Timeline
- 2024-08-27: advisory: Initial JVN advisory published
- 2024-08-30: disclosed: CVE published to NVD
- 2026-05-12: other: Affected product list updated in advisory