Medium severity6.1NVD Advisory· Published Jul 13, 2023· Updated Jun 17, 2026
CVE-2023-37560
CVE-2023-37560
Description
Cross-site scripting vulnerability in WRH-300WH-H v2.12 and earlier, and WTC-300HWH v1.09 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6<=2.12+ 1 more
- (no CPE)range: <=2.12
- (no CPE)range: v2.12 and earlier
<=1.09+ 1 more
- (no CPE)range: <=1.09
- (no CPE)range: v1.09 and earlier
- cpe:2.3:o:elecom:wrh-300wh-h_firmware:*:*:*:*:*:*:*:*Range: <=2.12
- cpe:2.3:o:elecom:wtc-300hwh_firmware:*:*:*:*:*:*:*:*Range: <=1.09
Patches
Vulnerability mechanics
References
2- jvn.jp/en/jp/JVN05223215/nvdThird Party Advisory
- www.elecom.co.jp/news/security/20230711-01/nvdVendor Advisory
News mentions
0No linked articles in our index yet.