Executive brief
A security vulnerability has been identified in several ELECOM wireless LAN routers. These devices are used to provide Wi-Fi and network connectivity in homes and small offices. If an attacker gains access to a user account on the device, they can take complete control of the router, potentially leading to data interception or network disruption.
Technical details
An OS command injection vulnerability (CWE-78) exists in the management interface of various ELECOM wireless LAN routers. The flaw is triggered when the application fails to properly neutralize special elements in a crafted request sent by an authenticated user. An attacker with valid login credentials can exploit this to execute arbitrary OS commands with the privileges of the web server. This could lead to full system compromise, unauthorized configuration changes, or persistent access to the local network. Firmware updates have been released for supported models to address this issue.
Affected products
- ELECOM WRC-X1500GS-B firmware v1.12 and earlier
- ELECOM WRC-X1500GSA-B firmware v1.12 and earlier
- ELECOM WRC-X3000GS2-B firmware v1.09 and earlier
- ELECOM WRC-X3000GS2-W firmware v1.09 and earlier
- ELECOM WRC-X3000GS2A-B firmware v1.09 and earlier
- ELECOM WRC-X3000GST2-B firmware v1.06 and earlier
- ELECOM WRC-X1800GS-B firmware v1.19 and earlier
- ELECOM WRC-X1800GSA-B firmware v1.19 and earlier
- ELECOM WRC-X1800GSH-B firmware v1.19 and earlier
- ELECOM WRC-X6000QS-G firmware v1.14 and earlier
- ELECOM, WRC-X6000QSA-G firmware v1.14 and earlier
- ELECOM WRC-X6000XS-G firmware v1.12 and earlier
- ELECOM WRC-X6000XST-G firmware v1.16 and earlier
- ELECOM WRC-XE5400GS-G firmware v1.13 and earlier
- ELECOM WRC-XE5400GSA-G firmware v1.13 and earlier
Timeline
- 2026-02-03: disclosed
- 2026-02-03: advisory
- 2026-05-12: other: Advisory updated with additional affected products.