« Volver al listado

CVE-2021-20862

Estado: ModificadaMedia (4.3)—

Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent unauthenticated attacker to bypass access restriction, and to obtain anti-CSRF tokens and change the product's settings via unspecified vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (14)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-20862",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.3,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 6.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "ELECOM CO.,LTD.",
          "product": "ELECOM routers",
          "versions": [
            {
              "status": "affected",
              "version": "(WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior)"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-12-01T03:15:07.173",
  "references": [
    {
      "url": "https://jvn.jp/en/vu/JVNVU94527926/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.elecom.co.jp/news/security/20211130-01/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/vu/JVNVU94527926/index.html",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.elecom.co.jp/news/security/20211130-01/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware v1.03 and prior, WRC-1750GSV firmware v2.11 and prior, WRC-1900GST firmware v1.03 and prior, WRC-2533GST firmware v1.03 and prior, WRC-2533GSTA firmware v1.03 and prior, WRC-2533GST2 firmware v1.25 and prior, WRC-2533GST2SP firmware v1.25 and prior, WRC-2533GST2-G firmware v1.25 and prior, and EDWRC-2533GST2 firmware v1.25 and prior) allows a network-adjacent unauthenticated attacker to bypass access restriction, and to obtain anti-CSRF tokens and change the product's settings via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de control de acceso inapropiado en los routers ELECOM (firmware WRC-1167GST2 versiones v1.25 y anteriores, firmware WRC-1167GST2A versiones v1.25 y anteriores, firmware WRC-1167GST2H versiones v1.25 y anteriores, firmware WRC-2533GS2-B versiones v1. 52 y anteriores, firmware WRC-2533GS2-W versiones v1.52 y anteriores, firmware WRC-1750GS versiones v1.03 y anteriores, firmware WRC-1750GSV versiones v2.11 y anteriores, firmware WRC-1900GST versiones v1.03 y anteriores, firmware WRC-2533GST versiones v1.03 y anteriores, firmware WRC-2533GSTA v1.03 y anteriores, firmware WRC-2533GST2 v1.25 y anteriores, firmware WRC-2533GST2SP v1.25 y anteriores, firmware WRC-2533GST2-G v1.25 y anteriores, y firmware EDWRC-2533GST2 v1. 25 y anteriores) permite a un atacante no autenticado adyacente a la red omitir la restricción de acceso y obtener tokens anti-CSRF y cambiar la configuración del producto por medio de vectores no especificados"
    }
  ],
  "lastModified": "2026-06-17T03:34:33.633",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-1167gst2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D3AA3E1E-07AE-4152-A492-C3399A944BF7",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-1167gst2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "F9045F74-985E-4C3C-AC10-14FD9B61A746"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-1167gst2a_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AC52913C-AD35-469D-8F67-0CBD929E7CC5",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-1167gst2a:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A33E8405-7457-4867-A4A5-360E173F69C3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-1167gst2h_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9E89A906-6747-4375-9027-598803400260",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-1167gst2h:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "56272E8D-141C-4BBC-9950-BD673DE78DF7"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gs2-b_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "838C19DE-7992-40DB-996B-9F3F2C0A6B5B",
              "versionEndIncluding": "1.52"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gs2-b:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "D9FF3CB7-7F2E-472A-A2A3-ED599F4FC99C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gs2-w_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBD1BE1F-5197-4EFD-B34F-D39D97E07900",
              "versionEndIncluding": "1.52"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gs2-w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "ECD9F0FE-1232-4C39-AA86-2D616E4D39C6"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-1750gs_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0B90ED83-CB98-452B-A34C-F86256F2C1FF",
              "versionEndIncluding": "1.03"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-1750gs:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5F0C77E9-CD6E-498E-954B-A930EDB56CEB"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-1750gsv_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A65A768-A630-4804-9746-FCBBF17EEC63",
              "versionEndIncluding": "2.11"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-1750gsv:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "B805C94F-F3EA-4DF2-9BD0-82F5A3CC1AA3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-1900gst_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8A570270-DF00-4D05-8E38-09F465E4B4CA",
              "versionEndIncluding": "1.03"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-1900gst:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "C37FA743-9A1C-4817-9002-5B4A0D55EB30"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gst_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "20A7CDAF-5B21-4D45-AEE7-F23374ABE11D",
              "versionEndIncluding": "1.03"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gst:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "061E2CC5-C26D-4A99-B7B6-7AA16EA61FE0"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gst2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BFCF93B-086E-4566-B80C-2698526059ED",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gst2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "85BF0A23-43C9-4497-BDDF-9366642503ED"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gsta_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C6BA52A2-79CF-4111-ADD9-F567CD7B6982",
              "versionEndIncluding": "1.03"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gsta:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "8A7E273D-FE44-4028-8A24-2E2F5346A8E8"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gst2sp_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78429AAB-582E-4E65-886F-3154B76B6F26",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gst2sp:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "87DCC539-2464-401D-BEDD-21D8F89D52E3"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:wrc-2533gst2-g_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DF24D0CA-259A-48A3-A0C0-BBDA737BCEF8",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:wrc-2533gst2-g:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "52CFBBB2-A29E-49EC-9FF6-265C92C01D88"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:elecom:edwrc-2533gst2_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D1D5B7C7-E77F-43C5-AD15-EA9F9DA384A1",
              "versionEndIncluding": "1.25"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:elecom:edwrc-2533gst2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "92158669-E6B4-4079-84F8-F86B7F288E24"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}