Vulnerability Details CVE-2024-34577
Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, and WRC-X3000GS2A-B due to improper processing of input values in easysetup.cgi. If a user views a malicious web page while logged in to the product, an arbitrary script may be executed on the user's web browser.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 42.3%
CVSS Severity
CVSS v3 Score 6.1
Products affected by CVE-2024-34577
-
cpe:2.3:h:elecom:wrc-x3000gs2-b:-
-
cpe:2.3:h:elecom:wrc-x3000gs2-w:-
-
cpe:2.3:h:elecom:wrc-x3000gs2a-b:-
-
cpe:2.3:o:elecom:wrc-x3000gs2-b_firmware:-
-
cpe:2.3:o:elecom:wrc-x3000gs2-b_firmware:1.08
-
cpe:2.3:o:elecom:wrc-x3000gs2-w_firmware:-
-
cpe:2.3:o:elecom:wrc-x3000gs2-w_firmware:1.08
-
cpe:2.3:o:elecom:wrc-x3000gs2a-b_firmware:-
-
cpe:2.3:o:elecom:wrc-x3000gs2a-b_firmware:1.08