5.3
CVE-2025-36519
- EPSS 0.29%
- Veröffentlicht 24.06.2025 04:36:57
- Zuletzt bearbeitet 15.04.2026 00:35:42
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B,WRC-2533GS2-B v1.69 and earlier, WRC-2533GS2-W, WRC-1167GST2, WRC-1167GS2-B, and WRC-1167GS2H-B. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerELECOM CO.,LTD.
≫
Produkt
WRC-2533GST2
Version
v1.31 and earlier
Status
affected
HerstellerELECOM CO.,LTD.
≫
Produkt
WRC-1167GST2
Version
v1.34 and earlier
Status
affected
HerstellerELECOM CO.,LTD.
≫
Produkt
WRC-2533GS2V-B
Version
v1.69 and earlier
Status
affected
HerstellerELECOM CO.,LTD.
≫
Produkt
WRC-2533GS2-B
Version
v1.69 and earlier
Status
affected
HerstellerELECOM CO.,LTD.
≫
Produkt
WRC-2533GS2-W
Version
v1.69 and earlier
Status
affected
HerstellerELECOM CO.,LTD.
≫
Produkt
WRC-1167GS2-B
Version
v1.74 and earlier
Status
affected
HerstellerELECOM CO.,LTD.
≫
Produkt
WRC-1167GS2H-B
Version
v1.74 and earlier
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.29% | 0.205 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| vultures@jpcert.or.jp | 5.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| vultures@jpcert.or.jp | 4.3 | 2.8 | 1.4 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
https://www.elecom.co.jp/news/security/20250624-01/
https://jvn.jp/en/jp/JVN39435597/