Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators and to perform unintended operations to the affected product. Note that WMC-X1800GST-B and WSC-X1800GS-B are also included in e-Mesh Starter Kit "WMC-2LX-B".
Conclusion & alert: CVE-2024-23910 is rated Moderate Risk (50.2/100): CVSS High severity, with low exploitation likelihood (EPSS 0.21%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-09-01 | 0.41% | 0.21% | -0.20% |
| 2 | 2025-04-30 | 0.47% | 0.41% | -0.06% |
| 3 | 2025-04-15 | — | 0.47% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 4.3 | 3.0 | MEDIUM |
|
2.8 | 1.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| elecom | wrc-1167gs2-b_firmware | < 1.73 | cpe:2.3:o:elecom:wrc-1167gs2-b_firmware:*:*:*:*:*:*:*:* |
| elecom | wrc-1167gs2h-b_firmware | < 1.73 | cpe:2.3:o:elecom:wrc-1167gs2h-b_firmware:*:*:*:*:*:*:*:* |
| elecom | wrc-1167gst2_firmware | < 1.34 | cpe:2.3:o:elecom:wrc-1167gst2_firmware:*:*:*:*:*:*:*:* |
| elecom | wrc-2533gs2-b_firmware | < 1.68 | cpe:2.3:o:elecom:wrc-2533gs2-b_firmware:*:*:*:*:*:*:*:* |
| elecom | wrc-2533gs2-w_firmware | < 1.68 | cpe:2.3:o:elecom:wrc-2533gs2-w_firmware:*:*:*:*:*:*:*:* |
| elecom | wrc-2533gs2v-b_firmware | < 1.68 | cpe:2.3:o:elecom:wrc-2533gs2v-b_firmware:*:*:*:*:*:*:*:* |
| elecom | wrc-2533gst2_firmware | < 1.31 | cpe:2.3:o:elecom:wrc-2533gst2_firmware:*:*:*:*:*:*:*:* |
| elecom | wrc-x3200gst3-b_firmware | < 1.27 | cpe:2.3:o:elecom:wrc-x3200gst3-b_firmware:*:*:*:*:*:*:*:* |
| elecom | wrc-g01-w_firmware | < 1.26 | cpe:2.3:o:elecom:wrc-g01-w_firmware:*:*:*:*:*:*:*:* |
| elecom | wmc-x1800gst-b_firmware | < 1.42 | cpe:2.3:o:elecom:wmc-x1800gst-b_firmware:*:*:*:*:*:*:*:* |
| elecom | wsc-x1800gs-b_firmware | < 1.42 | cpe:2.3:o:elecom:wsc-x1800gs-b_firmware:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://jvn.jp/en/jp/JVN44166658/ | Third Party Advisory |
| https://www.elecom.co.jp/news/security/20240220-01/ | Vendor Advisory |