CVE-2026-22550

OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command execution.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:elecom:wrc-x1500gsa-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1500gsa-b:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:elecom:wrc-x1500gs-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1500gs-b:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-03 07:16

Updated : 2026-06-17 10:20


NVD link : CVE-2026-22550

Mitre link : CVE-2026-22550

CVE.ORG link : CVE-2026-22550


JSON object : View

Products Affected

elecom

  • wrc-x1500gsa-b
  • wrc-x1500gs-b_firmware
  • wrc-x1500gsa-b_firmware
  • wrc-x1500gs-b
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')