{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-08T02:47:54.546","vulnerabilities":[{"cve":{"id":"CVE-2023-37566","sourceIdentifier":"vultures@jpcert.or.jp","published":"2023-07-13T02:15:09.517","lastModified":"2024-11-21T08:11:57.690","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a network-adjacent authenticated attacker to execute an arbitrary command by sending a specially crafted request to the web management page. Affected products and versions are as follows: WRC-1167GHBK3-A v1.24 and earlier, WRC-1167FEBK-A v1.18 and earlier, WRC-F1167ACF2 all versions, WRC-600GHBK-A all versions, WRC-733FEBK2-A all versions, WRC-1467GHBK-A all versions, WRC-1900GHBK-A all versions, and LAN-W301NR all versions."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"ADJACENT_NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:elecom:wrc-1167ghbk3-a_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.24","matchCriteriaId":"CDA47F4E-73D6-4F96-8EF4-8896701F6990"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:elecom:wrc-1167ghbk3-a:-:*:*:*:*:*:*:*","matchCriteriaId":"C6248727-0D48-44DA-A44A-87FD71ECEDA6"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:elecom:wrc-1167febk-a_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.18","matchCriteriaId":"2FA6AB13-9CBF-46A1-89E8-1D341E6FBE03"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:elecom:wrc-1167febk-a:-:*:*:*:*:*:*:*","matchCriteriaId":"9F6BA0C4-7C5C-4BF3-A268-4978590041E6"}]}]}],"references":[{"url":"https://jvn.jp/en/vu/JVNVU91850798/","source":"vultures@jpcert.or.jp","tags":["Third Party Advisory"]},{"url":"https://www.elecom.co.jp/news/security/20230711-01/","source":"vultures@jpcert.or.jp","tags":["Vendor Advisory"]},{"url":"https://www.elecom.co.jp/news/security/20230810-01/","source":"vultures@jpcert.or.jp"},{"url":"https://jvn.jp/en/vu/JVNVU91850798/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.elecom.co.jp/news/security/20230711-01/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.elecom.co.jp/news/security/20230810-01/","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}