CVE-2024-34577: Elecom Wrc-x3000gs2-B Firmware

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B and WRC-X3000GST2-B due to improper processing of input values in easysetup.cgi. If a user views a malicious web page while logged in to the product, an arbitrary script may be executed on the user's web browser.

Affected products

  • Elecom Wrc-x3000gs2-B Firmware: up to and including 1.08
  • Elecom Wrc-x3000gs2-W Firmware: up to and including 1.08
  • Elecom Wrc-x3000gs2a-B Firmware: up to and including 1.08

Published 2024-08-30. Last modified 2026-06-17.