VYPR

Vendor CVEs

ELECOM CO.,LTD.

All CVEs

93 total · sorted by risk
  • CVE-2023-49695MedDec 12, 2023
    risk 0.44cvss 6.8epss 0.01

    OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command by sending a specially crafted request to the…

  • CVE-2021-20854MedDec 1, 2021
    risk 0.44cvss 6.8epss 0.00

    ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS commands via unspecified vectors.

  • CVE-2021-20853MedDec 1, 2021
    risk 0.44cvss 6.8epss 0.00

    ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS commands via unspecified vectors.

  • CVE-2021-20852MedDec 1, 2021
    risk 0.44cvss 6.8epss 0.00

    Buffer overflow vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute an arbitrary OS command via unspecified vectors.

  • CVE-2021-20648MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.00

    ELECOM WRC-300FEBK-S allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.

  • CVE-2021-20640MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.01

    Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command via unspecified vectors.

  • CVE-2021-20639MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.00

    LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

  • CVE-2021-20638MedFeb 12, 2021
    risk 0.44cvss 6.8epss 0.00

    LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

  • CVE-2026-25107MedMay 13, 2026
    risk 0.42cvss 6.5epss 0.00

    ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted…

  • CVE-2023-43757MedNov 16, 2023
    risk 0.42cvss 6.5epss 0.01

    Inadequate encryption strength vulnerability in multiple routers provided by ELECOM CO.,LTD. and LOGITEC CORPORATION allows a network-adjacent unauthenticated attacker to guess the encryption key used for wireless LAN communication and intercept the communication. As for the…

  • CVE-2023-37563MedJul 13, 2023
    risk 0.42cvss 6.5epss 0.00

    ELECOM wireless LAN routers are vulnerable to sensitive information exposure, which allows a network-adjacent unauthorized attacker to obtain sensitive information. Affected products and versions are as follows: WRC-1167GHBK-S v1.03 and earlier, WRC-1167GEBK-S v1.03 and earlier,…

  • CVE-2021-20738MedJul 7, 2021
    risk 0.42cvss 6.5epss 0.00

    WRC-1167FS-W, WRC-1167FS-B, and WRC-1167FSA all versions allow an unauthenticated network-adjacent attacker to obtain sensitive information via unspecified vectors.

  • CVE-2021-20650MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in ELECOM NCC-EWF100RMWH2 allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be…

  • CVE-2021-20647MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-S allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be…

  • CVE-2021-20646MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-A allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be…

  • CVE-2021-20642MedFeb 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) condition by sending a specially crafted URL.

  • CVE-2024-42412MedAug 30, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting vulnerability exists in ELECOM wireless access points due to improper processing of input values in menu.cgi. If a user views a malicious web page while logged in to the product, an arbitrary script may be executed on the user's web browser.

  • CVE-2024-34577MedAug 30, 2024
    risk 0.40cvss 6.1epss 0.00

    Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, WRC-X3000GS2A-B and WRC-X3000GST2-B due to improper processing of input values in easysetup.cgi. If a user views a malicious web page while logged in to the product, an arbitrary script may be executed…

  • CVE-2023-37561MedJul 13, 2023
    risk 0.40cvss 6.1epss 0.00

    Open redirect vulnerability in ELECOM wireless LAN routers and ELECOM wireless LAN repeaters allows a remote unauthenticated attacker to redirect users to arbitrary web sites and conduct phishing attacks via a specially crafted URL. Affected products and versions are as follows:…

  • CVE-2023-37560MedJul 13, 2023
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in WRH-300WH-H v2.12 and earlier, and WTC-300HWH v1.09 and earlier allows a remote unauthenticated attacker to inject an arbitrary script.

  • CVE-2021-20644MedFeb 12, 2021
    risk 0.40cvss 6.1epss 0.01

    ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web setup page.

  • CVE-2025-43877MedJun 24, 2025
    risk 0.35cvss 5.4epss 0.00

    WRC-1167GHBK2-S contains a stored cross-site scripting vulnerability in WebGUI. If exploited, an arbitrary script may be executed on the web browser of the user who accessed WebGUI of the product.

  • CVE-2021-20858MedDec 1, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20857MedDec 1, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20856MedDec 1, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20855MedDec 1, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a remote authenticated attacker to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20645MedFeb 12, 2021
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting vulnerability in ELECOM WRC-300FEBK-A allows remote authenticated attackers to inject arbitrary script via unspecified vectors.

  • CVE-2022-21799MedFeb 8, 2022
    risk 0.34cvss 5.2epss 0.00

    Cross-site scripting vulnerability in ELECOM LAN router WRC-300FEBK-R firmware v1.13 and earlier allows an attacker on the adjacent network to inject an arbitrary script via unspecified vectors.

  • CVE-2025-46267MedJul 22, 2025
    risk 0.32cvss 4.9epss 0.00

    Hidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited, the product's hidden debug function may be enabled by a remote attacker who can log in to WebGUI.

  • CVE-2026-42948MedMay 13, 2026
    risk 0.31cvss 4.8epss 0.00

    Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser.

  • CVE-2024-21798MedFeb 28, 2024
    risk 0.31cvss 4.8epss 0.01

    ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be…

  • CVE-2021-20649MedFeb 12, 2021
    risk 0.31cvss 4.8epss 0.00

    ELECOM WRC-300FEBK-S contains an improper certificate validation vulnerability. Via a man-in-the-middle attack, an attacker may alter the communication response. As a result, an arbitrary OS command may be executed on the affected device.

  • CVE-2026-24449MedFeb 3, 2026
    risk 0.30cvss 4.6epss 0.00

    For WRC-X1500GS-B and WRC-X1500GSA-B, the initial passwords can be calculated easily from the system information.

  • CVE-2026-42961MedMay 13, 2026
    risk 0.28cvss 4.3epss 0.00

    ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.

  • CVE-2026-42950MedMay 13, 2026
    risk 0.28cvss 4.3epss 0.00

    ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken.

  • CVE-2026-20704MedFeb 3, 2026
    risk 0.28cvss 4.3epss 0.00

    Cross-site request forgery vulnerability exists in ELECOM wireless LAN products. If a user accesses a malicious page while logged-in to the affected product, unintended operations may be performed.

  • CVE-2025-36519MedJun 24, 2025
    risk 0.28cvss 4.3epss 0.00

    Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B,WRC-2533GS2-B v1.69 and earlier, WRC-2533GS2-W, WRC-1167GST2, WRC-1167GS2-B, and WRC-1167GS2H-B. If a specially crafted file is uploaded by a remote…

  • CVE-2024-29225MedApr 4, 2024
    risk 0.28cvss 4.3epss 0.00

    ELECOM wireless LAN routers allow a network-adjacent unauthenticated attacker to obtain the configuration file containing sensitive information by sending a specially crafted request.

  • CVE-2021-20862MedDec 1, 2021
    risk 0.28cvss 4.3epss 0.00

    Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-2533GS2-B firmware v1.52 and prior, WRC-2533GS2-W firmware v1.52 and prior, WRC-1750GS firmware…

  • CVE-2024-39300LowAug 30, 2024
    risk 0.24cvss 3.7epss 0.00

    Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function of the product is enabled, a remote attacker may login to the product without authentication and alter the product's settings.

  • CVE-2026-61376HigJul 28, 2026
    risk 0.00cvss 7.2epss 0.01

    ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

  • CVE-2026-59764HigJul 28, 2026
    risk 0.00cvss 7.2epss 0.01

    ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

  • CVE-2026-44387MedJul 28, 2026
    risk 0.00cvss 5.2epss 0.00

    ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser.

Page 2 of 2