OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command execution.
References
| Link | Resource |
|---|---|
| https://jvn.jp/en/jp/JVN94012927/ | Third Party Advisory |
| https://www.elecom.co.jp/news/security/20260203-01/ | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-02-03 07:16
Updated : 2026-06-17 10:20
NVD link : CVE-2026-22550
Mitre link : CVE-2026-22550
CVE.ORG link : CVE-2026-22550
JSON object : View
Products Affected
elecom
- wrc-x1500gsa-b
- wrc-x1500gs-b_firmware
- wrc-x1500gsa-b_firmware
- wrc-x1500gs-b
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
