CVE-2024-34021: Unrestricted upload of file with dangerous type in ELECOM CO.,LTD. WRC-1167GST2
Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product by a logged-in user with an administrative privilege, resulting in an arbitrary OS command execution.
AI Analysis
Technical Summary
This vulnerability (CVE-2024-34021) affects ELECOM WRC-1167GST2 routers running firmware version 1.32 or earlier. It allows an authenticated user with administrative privileges to upload files of dangerous types without proper validation or restriction. Successful exploitation results in arbitrary OS command execution, which can compromise the device's integrity and availability. The CVSS 3.0 base score is 6.8, reflecting medium severity with high impact on confidentiality, integrity, and availability. No vendor patch or official fix information is available at this time.
Potential Impact
An attacker with administrative access to the router can upload malicious files that lead to arbitrary OS command execution. This can result in full compromise of the device, including unauthorized control, data manipulation, or denial of service. The vulnerability requires administrative privileges and no user interaction, limiting exposure to trusted users but increasing risk if credentials are compromised.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict administrative access to trusted personnel only and monitor for unauthorized access. Avoid uploading files to the device unless necessary and verify file types carefully. Follow ELECOM's official channels for updates on patches or mitigations.
CVE-2024-34021: Unrestricted upload of file with dangerous type in ELECOM CO.,LTD. WRC-1167GST2
Description
Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product by a logged-in user with an administrative privilege, resulting in an arbitrary OS command execution.
CVSS v3.0
Score 6.8medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2024-34021) affects ELECOM WRC-1167GST2 routers running firmware version 1.32 or earlier. It allows an authenticated user with administrative privileges to upload files of dangerous types without proper validation or restriction. Successful exploitation results in arbitrary OS command execution, which can compromise the device's integrity and availability. The CVSS 3.0 base score is 6.8, reflecting medium severity with high impact on confidentiality, integrity, and availability. No vendor patch or official fix information is available at this time.
Potential Impact
An attacker with administrative access to the router can upload malicious files that lead to arbitrary OS command execution. This can result in full compromise of the device, including unauthorized control, data manipulation, or denial of service. The vulnerability requires administrative privileges and no user interaction, limiting exposure to trusted users but increasing risk if credentials are compromised.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict administrative access to trusted personnel only and monitor for unauthorized access. Avoid uploading files to the device unless necessary and verify file types carefully. Follow ELECOM's official channels for updates on patches or mitigations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- jpcert
- Date Reserved
- 2024-07-26T08:52:16.452Z
- Cvss Version
- 3.0
- State
- PUBLISHED
Threat ID: 6981ae8df9fa50a62faf0c0d
Added to database: 2/3/2026, 8:15:09 AM
Last enriched: 5/13/2026, 2:46:21 AM
Last updated: 6/19/2026, 3:34:25 PM
Views: 142
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.