HIGHCVE-2026-22550Published Modified CNA jpcert
CVE-2026-22550: OS command injection vulnerability exists in ELECOM wireless LAN products
OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command execution.
Metrics
- CVSS v4.0
- 8.6
- Severity
- HIGH
- Fixed in
- —
- Affected Products
- 15
Affected packages
- ELECOM CO.,LTD. / WRC-X6000XS-Gv1.12 and earlier
- ELECOM CO.,LTD. / WRC-X6000XST-Gv1.16 and earlier
- ELECOM CO.,LTD. / WRC-XE5400GS-Gv1.13 and earlier
- ELECOM CO.,LTD. / WRC-XE5400GSA-Gv1.13 and earlier
- ELECOM CO.,LTD. / WRC-X1500GS-Bv1.12 and earlier
- ELECOM CO.,LTD. / WRC-X1500GSA-Bv1.12 and earlier
- ELECOM CO.,LTD. / WRC-X3000GS2-Bv1.09 and earlier
- ELECOM CO.,LTD. / WRC-X3000GS2-Wv1.09 and earlier
- ELECOM CO.,LTD. / WRC-X3000GS2A-Bv1.09 and earlier
- ELECOM CO.,LTD. / WRC-X3000GST2-Bv1.06 and earlier
- ELECOM CO.,LTD. / WRC-X1800GS-Bv1.19 and earlier
- ELECOM CO.,LTD. / WRC-X1800GSA-Bv1.19 and earlier
- ELECOM CO.,LTD. / WRC-X1800GSH-Bv1.19 and earlier
- ELECOM CO.,LTD. / WRC-X6000QS-Gv1.14 and earlier
- ELECOM CO.,LTD. / WRC-X6000QSA-Gv1.14 and earlier
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NReferences