Description
Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent unauthenticated attacker to bypass access restriction, and to start the telnet service and execute an arbitrary OS command via unspecified vectors.
Published: 2021-12-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-8273 Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent unauthenticated attacker to bypass access restriction, and to start the telnet service and execute an arbitrary OS command via unspecified vectors.
History

No history.

Subscriptions

Elecom Edwrc-2533gst2 Edwrc-2533gst2 Firmware Wrc-1167gst2 Wrc-1167gst2 Firmware Wrc-1167gst2a Wrc-1167gst2a Firmware Wrc-1167gst2h Wrc-1167gst2h Firmware Wrc-1750gs Wrc-1750gs Firmware Wrc-1750gsv Wrc-1750gsv Firmware Wrc-1900gst Wrc-1900gst Firmware Wrc-2533gs2-b Wrc-2533gs2-b Firmware Wrc-2533gs2-w Wrc-2533gs2-w Firmware Wrc-2533gst Wrc-2533gst2 Wrc-2533gst2-g Wrc-2533gst2-g Firmware Wrc-2533gst2 Firmware Wrc-2533gst2sp Wrc-2533gst2sp Firmware Wrc-2533gst Firmware Wrc-2533gsta Wrc-2533gsta Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2024-08-03T17:53:22.628Z

Reserved: 2020-12-17T00:00:00.000Z

Link: CVE-2021-20864

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-12-01T03:15:07.273

Modified: 2024-11-21T05:47:18.223

Link: CVE-2021-20864

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses