ELECOM WRC-BE72XSD-B
cpe:2.3:h:elecom:wrc-x1800gsa-b:*:*:*:*:*:*:*, +7 more
- <= 1.19
- <= 1.09
A command injection vulnerability has been identified in several models of ELECOM wireless LAN access points and routers. This vulnerability arises from improper handling of the username parameter, allowing authenticated users to execute arbitrary OS commands. The issue is present in multiple device models and versions, with no authentication required for exploitation.
Exploitation of this vulnerability allows for arbitrary OS command execution on the affected device, without the need for authentication.
Users are advised to update the firmware to the latest version available for their specific device model.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.