CVE Intelligence
Skip to main content
MEDIUM

CVE-2024-25579

CVE-2024-25579 Vulnerability Analysis & Exploit Intelligence

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to the product. Note that WMC-X1800GST-B is also included in e-Mesh Starter Kit "WMC-2LX-B".

Published Updated Sources: cvelistV5, jpcert

Triage

Is it exploited, how likely is exploitation, what does it touch, and how severe do the scoring sources call it.

Exploitation

Unreported

no source claims exploitation

EPSS

1%

chance of exploitation in 30 days

Affects

elecom co

23 products listed

CVSS base

6.8

MEDIUM

CISA SSVC assessment

Three decision points CISA publishes for the CVEs it assesses · SSVC 2.0.3. A stakeholder decision, not a severity score.

CISA

Exploitation

None

none · proof-of-concept · active

Automatable

No

can an attacker script all four kill-chain steps

Technical impact

Total

partial · total control of the vulnerable component

Affected scope

The catalog records vendors and products as separate lists, not pairs, so which product belongs to which vendor is not something this page can say.

Vendors (2)

Products (23)

wrc 1167gs2 bwrc 1167gs2h bwrc 1167gst2wrc 2533gs2 bwrc 2533gs2 wwrc 2533gs2v bwrc 2533gst2wrc x3200gst3 bwrc g01 wwmc x1800gst bwmc 2lx2 bwmc x1800gst2 bwsc x1800gs2 bwrc 1167gs2 b firmwarewrc 1167gs2h b firmwarewrc 2533gs2 b firmwarewrc 2533gs2 w firmwarewrc 2533gs2v b firmwarewrc x3200gst3 b firmwarewrc g01 w firmwarewmc x1800gst b firmwarewrc 1167gst2 firmwarewrc 2533gst2 firmware

Every base score collected

Sources score independently and disagree; each row says who scored it and under which version.

ScoreVersionSeverityExpl.ImpactSource
6.8CVSS 3.1MEDIUMcvelistV5

Weakness & attack patterns

  • CWE-78

References

2 on the record

Elsewhere on this site

Not in any source we poll

Listed rather than left blank: an empty field and an unmeasured one look identical on screen, and only one is a reason to look elsewhere.

  • No confirmed IOCs, IP addresses, domains, file hashes, or malware artifacts supplied.
  • No organization-specific asset inventory, compensating-control status, or patch deployment evidence supplied.
  • No exploit packet captures, log samples, or incident case IDs supplied.