« Volver al listado

CVE-2021-20861

Estado: ModificadaAlta (8.8)—

Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent authenticated attacker to bypass access restriction and to access the management screen of the product via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (14)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-20861",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.8,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "ELECOM CO.,LTD.",
          "product": "ELECOM LAN routers",
          "versions": [
            {
              "status": "affected",
              "version": "WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-12-01T03:15:07.130",
  "references": [
    {
      "url": "https://jvn.jp/en/jp/JVN88993473/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.elecom.co.jp/news/security/20211130-01/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/jp/JVN88993473/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.elecom.co.jp/news/security/20211130-01/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent authenticated attacker to bypass access restriction and to access the management screen of the product via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de control de acceso inapropiado en los routers LAN de ELECOM (firmware WRC-1167GST2 versiones v1.25 y anteriores, firmware WRC-1167GST2A versiones v1.25 y anteriores, firmware WRC-1167GST2H versiones v1.25 y anteriores, firmware WRC-2533GS2-B versiones v1. 52 y anteriores, firmware WRC-2533GS2-W versiones v1.52 y anteriores, firmware WRC-1750GS versiones v1.03 y anteriores, firmware WRC-1750GSV versiones v2.11 y anteriores, firmware WRC-1900GST versiones v1.03 y anteriores, firmware WRC-2533GST versiones v1.03 y anteriores, firmware WRC-2533GSTA versiones v1.03 y anteriores, firmware WRC-2533GST2 versiones v1.25 y anteriores, firmware WRC-2533GST2SP versiones v1.25 y anteriores, firmware WRC-2533GST2-G versiones v1.25 y anteriores, y firmware EDWRC-2533GST2 versiones v1.25 y anteriores) permite a un atacante autenticado adyacente a la red omitir la restricción de acceso y acceder a la pantalla de administración del producto por medio de vectores no especificados"
    }
  ],
  "lastModified": "2026-06-17T03:34:33.507",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-1167gst2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3AA3E1E-07AE-4152-A492-C3399A944BF7",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-1167gst2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F9045F74-985E-4C3C-AC10-14FD9B61A746"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-1167gst2a_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC52913C-AD35-469D-8F67-0CBD929E7CC5",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-1167gst2a:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A33E8405-7457-4867-A4A5-360E173F69C3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-1167gst2h_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E89A906-6747-4375-9027-598803400260",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-1167gst2h:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "56272E8D-141C-4BBC-9950-BD673DE78DF7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gs2-b_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "838C19DE-7992-40DB-996B-9F3F2C0A6B5B",
              "versionEndIncluding": "1.52"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gs2-b:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D9FF3CB7-7F2E-472A-A2A3-ED599F4FC99C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gs2-w_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBD1BE1F-5197-4EFD-B34F-D39D97E07900",
              "versionEndIncluding": "1.52"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gs2-w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "ECD9F0FE-1232-4C39-AA86-2D616E4D39C6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-1750gs_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B90ED83-CB98-452B-A34C-F86256F2C1FF",
              "versionEndIncluding": "1.03"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-1750gs:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5F0C77E9-CD6E-498E-954B-A930EDB56CEB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-1750gsv_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A65A768-A630-4804-9746-FCBBF17EEC63",
              "versionEndIncluding": "2.11"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-1750gsv:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B805C94F-F3EA-4DF2-9BD0-82F5A3CC1AA3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-1900gst_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A570270-DF00-4D05-8E38-09F465E4B4CA",
              "versionEndIncluding": "1.03"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-1900gst:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C37FA743-9A1C-4817-9002-5B4A0D55EB30"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gst_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20A7CDAF-5B21-4D45-AEE7-F23374ABE11D",
              "versionEndIncluding": "1.03"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gst:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "061E2CC5-C26D-4A99-B7B6-7AA16EA61FE0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gst2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BFCF93B-086E-4566-B80C-2698526059ED",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gst2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "85BF0A23-43C9-4497-BDDF-9366642503ED"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gsta_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6BA52A2-79CF-4111-ADD9-F567CD7B6982",
              "versionEndIncluding": "1.03"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gsta:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8A7E273D-FE44-4028-8A24-2E2F5346A8E8"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gst2sp_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78429AAB-582E-4E65-886F-3154B76B6F26",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gst2sp:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "87DCC539-2464-401D-BEDD-21D8F89D52E3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gst2-g_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF24D0CA-259A-48A3-A0C0-BBDA737BCEF8",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gst2-g:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "52CFBBB2-A29E-49EC-9FF6-265C92C01D88"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:edwrc-2533gst2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1D5B7C7-E77F-43C5-AD15-EA9F9DA384A1",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:edwrc-2533gst2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "92158669-E6B4-4079-84F8-F86B7F288E24"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}