{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T03:02:22.349","vulnerabilities":[{"cve":{"id":"CVE-2024-34577","sourceIdentifier":"vultures@jpcert.or.jp","published":"2024-08-30T07:15:11.660","lastModified":"2026-06-17T07:33:39.550","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B and WRC-X3000GST2-B due to improper processing of input values in easysetup.cgi. If a user views a malicious web page while logged in to the product, an arbitrary script may be executed on the user's web browser."},{"lang":"es","value":"Existe una vulnerabilidad de Cross Site Scripting en WRC-X3000GS2-B, WRC-X3000GS2-W y WRC-X3000GS2A-B debido al procesamiento incorrecto de los valores de entrada en easysetup.cgi. Si un usuario visualiza una página web maliciosa mientras está conectado al producto, es posible que se ejecute una secuencia de comandos arbitraria en el navegador web del usuario."}],"affected":[{"source":"vultures@jpcert.or.jp","affectedData":[{"vendor":"ELECOM CO.,LTD.","product":"WRC-X3000GS2-B","versions":[{"version":"v1.08 and earlier","status":"affected"}]},{"vendor":"ELECOM CO.,LTD.","product":"WRC-X3000GS2-W","versions":[{"version":"v1.08 and earlier","status":"affected"}]},{"vendor":"ELECOM CO.,LTD.","product":"WRC-X3000GS2A-B","versions":[{"version":"v1.08 and earlier","status":"affected"}]},{"vendor":"ELECOM CO.,LTD.","product":"WRC-X3000GST2-B","versions":[{"version":"v1.06 and earlier","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","baseScore":6.1,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":2.7},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N","baseScore":4.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.1,"impactScore":2.5}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-30T14:24:29.112981Z","id":"CVE-2024-34577","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"vultures@jpcert.or.jp","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:elecom:wrc-x3000gs2-b_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.08","matchCriteriaId":"D125A4ED-8AB6-4A49-A806-A9FC65455669"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:elecom:wrc-x3000gs2-b:-:*:*:*:*:*:*:*","matchCriteriaId":"6D748C9E-0B14-404C-A0D7-4DD1DDF35C11"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:elecom:wrc-x3000gs2-w_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.08","matchCriteriaId":"B1D0B1E8-3E29-40F0-8E71-CC7B89BF8572"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:elecom:wrc-x3000gs2-w:-:*:*:*:*:*:*:*","matchCriteriaId":"70A7409C-3E07-4A7B-8248-F2090A74448B"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:elecom:wrc-x3000gs2a-b_firmware:*:*:*:*:*:*:*:*","versionEndIncluding":"1.08","matchCriteriaId":"09A8CB6C-57A5-4B67-A128-4ACCEDB19B85"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:elecom:wrc-x3000gs2a-b:-:*:*:*:*:*:*:*","matchCriteriaId":"E2DC2AA9-297E-4FAC-B64D-64A06ED4ED1F"}]}]}],"references":[{"url":"https://jvn.jp/en/jp/JVN24885537/","source":"vultures@jpcert.or.jp","tags":["Third Party Advisory"]},{"url":"https://www.elecom.co.jp/news/security/20240827-01/","source":"vultures@jpcert.or.jp","tags":["Vendor Advisory"]}]}}]}