CVE-2021-20854
Description
ELECOM WRH-733GBK/GWH LAN routers allow network-adjacent admins to execute arbitrary OS commands due to OS command injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ELECOM WRH-733GBK/GWH LAN routers allow network-adjacent admins to execute arbitrary OS commands due to OS command injection.
Vulnerability
The affected products are ELECOM LAN routers WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior. The vulnerability is an OS command injection (CWE-78) as described in [1]. The issue allows a network-adjacent attacker with administrator privileges to execute arbitrary OS commands via unspecified vectors.
Exploitation
An attacker must be network-adjacent (on the same network segment) and must have obtained administrator credentials or gained administrative access to the router's management interface. No user interaction is required beyond the attacker's own privileged actions. The exact vector is not publicly detailed, but the command injection occurs in a component accessible to authenticated administrators [1].
Impact
Successful exploitation allows the attacker to execute arbitrary OS commands on the device. This could lead to full compromise of the router, including disclosure of sensitive information, modification of device configuration, or use of the device as a pivot point for further attacks. The CVSS v3 base score is 6.8 (AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H), indicating high confidentiality, integrity, and availability impact [1].
Mitigation
ELECOM has released firmware updates: version v1.03.0 for both WRH-733GBK and WRH-733GWH. Users should update to the latest firmware. No workarounds are listed. The advisory was published November 30, 2021 [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <=1.02.9
- ELECOM CO.,LTD./ELECOM LAN routersv5Range: WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior
Patches
0No patches discovered yet.
Vulnerability mechanics
No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.
References
2- jvn.jp/en/jp/JVN88993473/index.htmlmitrex_refsource_MISC
- www.elecom.co.jp/news/security/20211130-01/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.