Junglewise Threat Intelligence

CVE-2026-25107: ELECOM Wireless LAN devices hard-coded key in configuration backups

CVE-2026-25107 · Severity: medium · CVSS 6.5 · Published 2026-05-13

Technologies: Elecom Wrc-X3000gs2-W, Elecom Wrc-X3000gs2a-B, Elecom Wrc-X3000gs2-B. Vendors: Elecom.

Executive brief

ELECOM wireless routers and access points use a fixed, non-secret encryption key when creating backup files of their settings. An attacker who knows this key can create a modified configuration file and trick a network administrator into uploading it to the device. If successful, this allows the attacker to change device settings, potentially compromising the security of the entire local network.

Technical details

A Use of Hard-coded Cryptographic Key (CWE-321) vulnerability exists in multiple ELECOM wireless LAN routers and access points. The affected devices utilize a static, hard-coded key to encrypt configuration backup files. An attacker with knowledge of this key can decrypt legitimate backups or generate malicious ones. The attack requires user interaction, as a victim administrator must be tricked into uploading and applying the crafted configuration file to the device. Successful exploitation allows the attacker to modify device parameters, which could lead to further compromise of the network infrastructure. Firmware updates have been released to address this issue.

Affected products

  • ELECOM WRC-X3000GS2-B v1.09 and earlier
  • ELECOM WRC-X3000GS2-W v1.09 and earlier
  • ELECOM WRC-X3000GS2A-B v1.09 and earlier
  • ELECOM WRC-X3000GST2-B v1.06 and earlier
  • ELECOM WRC-X1800GS-B v1.19 and earlier
  • ELECOM WRC-X1800GSA-B v1.19 and earlier
  • ELECOM WRC-X1800GSH-B v1.19 and earlier
  • ELECOM WRC-X6000QS-G v1.14 and earlier
  • ELECOM WRC-X6000QSA-G v1.14 and earlier
  • ELECOM, WRC-X6000XS-G v1.12 and earlier
  • ELECOM WRC-X6000XST-G v1.16 and earlier
  • ELECOM WRC-XE5400GS-G v1.13 and earlier
  • ELECOM WRC-XE5400GSA-G v1.13 and earlier

Timeline

  • 2026-05-12: advisory: Initial advisory published by JVN and ELECOM
  • 2026-05-13: disclosed: CVE published to NVD

References

Related threats