Inaba Denki Sangyo Wi-Fi AP Unit AC-WPS-11ac Series OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the web user interface settings page of Inaba Denki Sangyo Wi-Fi AP Unit 'AC-WPS-11ac series'. This vulnerability allows a remote attacker with login access to execute arbitrary operating system commands on the device.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution by a remote attacker with login credentials for the device.

Remediation

Users are advised to update the device's firmware to the latest version, v2.0.06.13P. If the firmware update is not feasible, consider implementing recommended workarounds such as restricting web UI access to wired LAN connections only.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.