CVE-2023-37561: Elecom Wrh-300wh-H Firmware

Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.

Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. Affected products and versions are as follows: WRH-300WH-H v2.12 and earlier, WTC-300HWH v1.09 and earlier, WTC-C1167GC-B v1.17 and earlier, and WTC-C1167GC-W v1.17 and earlier.

Affected products

  • Elecom Wrh-300wh-H Firmware: up to and including 2.12
  • Elecom Wtc-300hwh Firmware: up to and including 1.09
  • Elecom Wtc-c1167gc-B Firmware: up to and including 1.17
  • Elecom Wtc-c1167gc-W Firmware: up to and including 1.17

Published 2023-07-13. Last modified 2026-06-17.