CVE-2023-37560: Elecom Wrh-300wh-H Firmware

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability in WRH-300WH-H v2.12 and earlier, and WTC-300HWH v1.09 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.

Affected products

  • Elecom Wrh-300wh-H Firmware: up to and including 2.12
  • Elecom Wtc-300hwh Firmware: up to and including 1.09

Published 2023-07-13. Last modified 2026-06-17.