Executive brief
A security vulnerability exists in several ELECOM wireless routers that could allow an attacker to perform unauthorized actions on the device. If a logged-in administrator visits a malicious website, the attacker can trick the router into changing its settings without the user's knowledge. This could lead to unauthorized configuration changes that compromise the security of the local network.
Technical details
A Cross-Site Request Forgery (CSRF) vulnerability (CWE-352) exists in the web management interface of various ELECOM wireless LAN products. The vulnerability stems from insufficient validation of requests to ensure they originated from the intended user. An attacker can exploit this by tricking an authenticated administrator into visiting a malicious webpage, which then sends unauthorized requests to the router's management interface. Successful exploitation allows the attacker to perform unintended operations or modify device configurations. Firmware updates have been released for supported models to mitigate this issue.
Affected products
- ELECOM WRC-X1500GS-B v1.12 and earlier versions
- ELECOM WRC-X1500GSA-B v1.12 and earlier versions
- ELECOM WRC-X3000GS2-B v1.09 and earlier versions
- ELECOM WRC-X3000GS2-W v1.09 and earlier versions
- ELECOM WRC-X3000GS2A-B v1.09 and earlier versions
- ELECOM WRC-X3000GST2-B v1.06 and earlier versions
- ELECOM WRC-X1800GS-B v1.19 and earlier versions
- ELECOM WRC-X1800GSA-B v1.19 and earlier versions
- ELECOM WRC-X1800GSH-B v1.19 and earlier versions
- ELECOM WRC-X6000QS-G v1.14 and earlier version
- ELECOM, WRC-X6000QSA-G v1.14 and earlier versions
- ELECOM WRC-X6000XS-G v1.12 and earlier versions
- ELECOM WRC-X6000XST-G v1.16 and earlier versions
- ELECOM WRC-XE5400GS-G v1.13 and earlier versions
- ELECOM WRC-XE5400GSA-G v1.13 and earlier versions
Timeline
- 2026-02-03: disclosed
- 2026-02-03: advisory
- 2026-05-12: other: Advisory updated with additional affected products