Junglewise Threat Intelligence

CVE-2024-34577: Elecom WRC-X3000 Series XSS in easysetup.cgi

CVE-2024-34577 · Severity: medium · CVSS 6.1 · Published 2024-08-30

Technologies: Elecom Wrc-X3000gs2-W, Elecom Wrc-X3000gs2a-B, Elecom Wrc-X3000gs2-B. Vendors: Elecom.

Executive brief

Elecom wireless LAN routers are affected by a security flaw that could allow an attacker to execute malicious scripts in a user's web browser. This occurs if a logged-in administrator visits a specially crafted website while their router management session is active. An exploit could lead to unauthorized changes to router settings or the theft of session information, potentially compromising the security of the local network.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in multiple Elecom router models (WRC-X3000 series) due to improper neutralization of input values within the 'easysetup.cgi' script. The vulnerability is triggered when the application fails to properly sanitize user-supplied data before including it in the web response. An unauthenticated remote attacker can exploit this by enticing an authenticated user to visit a malicious URL or web page. Successful exploitation allows the execution of arbitrary JavaScript in the victim's browser, which can be used to hijack administrative sessions or modify device configurations. Firmware updates have been released to address this issue.

Affected products

  • Elecom WRC-X3000GS2-B v1.08 and earlier
  • Elecom WRC-X3000GS2-W v1.08 and earlier
  • Elecom WRC-X3000GS2A-B v1.08 and earlier
  • Elecom WRC-X3000GST2-B v1.06 and earlier

Timeline

  • 2024-08-27: advisory: Initial JVN advisory published
  • 2024-08-30: disclosed: CVE published to NVD
  • 2026-05-12: other: Affected product list updated in advisory

References

Related threats