Medium severity6.8NVD Advisory· Published Dec 12, 2023· Updated Jun 17, 2026
CVE-2023-49695
CVE-2023-49695
Description
OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command by sending a specially crafted request to the product.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:o:elecom:wrc-x3000gs_firmware:*:*:*:*:*:*:*:*Range: <=1.0.24
- cpe:2.3:o:elecom:wrc-x3000gsa_firmware:*:*:*:*:*:*:*:*Range: <=1.0.24
- cpe:2.3:o:elecom:wrc-x3000gsn_firmware:1.0.2:*:*:*:*:*:*:*
- Range: <=1.0.2
- Range: v1.0.24 and earlier
Patches
Vulnerability mechanics
References
2- jvn.jp/en/vu/JVNVU97499577/nvdThird Party Advisory
- www.elecom.co.jp/news/security/20231212-01/nvdVendor Advisory
News mentions
0No linked articles in our index yet.