LiveActive security incident?Get immediate response
CVE Record

CVE-2023-37561: Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remot...

Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. Affected products and versions are as follows: WRH-300WH-H v2.12 and earlier, WTC-300HWH v1.09 and earlier, WTC-C1167GC-B v1.17 and earlier, and WTC-C1167GC-W v1.17 and earlier.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This CVE affects specific ELECOM wireless routers and repeaters. A remote unauthenticated attacker could craft a URL that appears related to the device but redirects users to another website, enabling phishing. The provided sources do not show code execution, device takeover, CVSS scoring, or confirmed active exploitation.

Executive priority

Treat this as a phishing-enablement issue, not a confirmed infrastructure compromise. Prioritize inventory and vendor guidance review, especially for environments where these devices are still in use or visible to users.

Technical view

CVE-2023-37561 is an open redirect issue in listed ELECOM WRH and WTC wireless LAN products. A specially crafted URL can redirect users to arbitrary websites. Affected versions are WRH-300WH-H v2.12 and earlier, WTC-300HWH v1.09 and earlier, and WTC-C1167GC-B/W v1.17 and earlier.

Likely exposure

Exposure is limited to organizations or users operating the listed ELECOM router or repeater models at affected firmware versions. Risk is highest where users may trust device-hosted links or where device URLs are reachable and used in phishing campaigns.

Exploitation context

The sources describe remote unauthenticated exploitation for phishing through crafted URLs. The CVE is not listed as KEV in the provided bundle, and no cited source in the bundle confirms active exploitation in the wild.

Researcher notes

Evidence is limited to the CVE description, affected-version list, ELECOM advisory reference, and JVN reference. No CVSS, CWE, patch version, exploit proof, or KEV evidence is included in the provided bundle.

Mitigation direction

  • Inventory ELECOM wireless routers and repeaters for the affected model names.
  • Compare firmware versions against the affected version thresholds in the CVE description.
  • Review ELECOM and JVN advisories for vendor-approved updates, replacements, or mitigations.
  • Avoid sharing or trusting unsolicited links that reference affected device interfaces.
  • Remove unsupported affected devices if vendor guidance does not provide a safe path.

Validation and detection

  • Confirm whether WRH-300WH-H, WTC-300HWH, WTC-C1167GC-B, or WTC-C1167GC-W are deployed.
  • Record current firmware versions for each matching device.
  • Check whether any device version is at or below the affected threshold.
  • Review phishing reports for links involving affected ELECOM device URLs.
  • Track ELECOM and JVN advisory updates for remediation status.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2023-37561 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
ELECOM CO.,LTD.WRH-300WH-Hv2.12 and earlierListed
ELECOM CO.,LTD.WTC-300HWHv1.09 and earlierListed
ELECOM CO.,LTD.WTC-C1167GC-Bv1.17 and earlierListed
ELECOM CO.,LTD.WTC-C1167GC-Wv1.17 and earlierListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.