Security readout for executives and security teams
Plain-English summary
This CVE affects specific ELECOM wireless routers and repeaters. A remote unauthenticated attacker could craft a URL that appears related to the device but redirects users to another website, enabling phishing. The provided sources do not show code execution, device takeover, CVSS scoring, or confirmed active exploitation.
Executive priority
Treat this as a phishing-enablement issue, not a confirmed infrastructure compromise. Prioritize inventory and vendor guidance review, especially for environments where these devices are still in use or visible to users.
Technical view
CVE-2023-37561 is an open redirect issue in listed ELECOM WRH and WTC wireless LAN products. A specially crafted URL can redirect users to arbitrary websites. Affected versions are WRH-300WH-H v2.12 and earlier, WTC-300HWH v1.09 and earlier, and WTC-C1167GC-B/W v1.17 and earlier.
Likely exposure
Exposure is limited to organizations or users operating the listed ELECOM router or repeater models at affected firmware versions. Risk is highest where users may trust device-hosted links or where device URLs are reachable and used in phishing campaigns.
Exploitation context
The sources describe remote unauthenticated exploitation for phishing through crafted URLs. The CVE is not listed as KEV in the provided bundle, and no cited source in the bundle confirms active exploitation in the wild.
Researcher notes
Evidence is limited to the CVE description, affected-version list, ELECOM advisory reference, and JVN reference. No CVSS, CWE, patch version, exploit proof, or KEV evidence is included in the provided bundle.
Mitigation direction
- Inventory ELECOM wireless routers and repeaters for the affected model names.
- Compare firmware versions against the affected version thresholds in the CVE description.
- Review ELECOM and JVN advisories for vendor-approved updates, replacements, or mitigations.
- Avoid sharing or trusting unsolicited links that reference affected device interfaces.
- Remove unsupported affected devices if vendor guidance does not provide a safe path.
Validation and detection
- Confirm whether WRH-300WH-H, WTC-300HWH, WTC-C1167GC-B, or WTC-C1167GC-W are deployed.
- Record current firmware versions for each matching device.
- Check whether any device version is at or below the affected threshold.
- Review phishing reports for links involving affected ELECOM device URLs.
- Track ELECOM and JVN advisory updates for remediation status.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2023-37561 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.elecom.co.jp/news/security/20230711-01/CVE reference
- https://jvn.jp/en/jp/JVN05223215/CVE reference
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
