ElecomCVEs & Vulnerabilities

63 CVEs affecting Elecom products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

wrc-2533gs2-b firmware 10wrc-2533gst2 10wrc-2533gs2-b 10wrc-1167gst2 10wrc-2533gs2-w 10wrc-2533gs2-w firmware 10wrc-1167gst2 firmware 10wrc-2533gst2 firmware 10
CVE-2021-20854MEDIUM

ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS commands via unspecified vectors.

1 Dec 2021
6.8
CVSS
CVE-2021-20853MEDIUM

ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute arbitrary OS commands via unspecified vectors.

1 Dec 2021
6.8
CVSS
CVE-2021-20852MEDIUM

Buffer overflow vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) allows a network-adjacent attacker with an administrator privilege to execute an arbitrary OS command via unspecified vectors.

1 Dec 2021
6.8
CVSS
CVE-2021-20739HIGH

WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all versions allows an unauthenticated network-adjacent attacker to execute an arbitrary OS command via unspecified vectors.

7 Jul 2021
8.8
CVSS
CVE-2021-20738MEDIUM

WRC-1167FS-W, WRC-1167FS-B, and WRC-1167FSA all versions allow an unauthenticated network-adjacent attacker to obtain sensitive information via unspecified vectors.

7 Jul 2021
6.5
CVSS
CVE-2021-20651CRITICAL

Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary file or overwrite an existing file in a directory which can be accessed with the application privileges via unspecified vectors.

12 Feb 2021
9.1
CVSS
CVE-2021-20650MEDIUM

Cross-site request forgery (CSRF) vulnerability in ELECOM NCC-EWF100RMWH2 allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be started.

12 Feb 2021
6.5
CVSS
CVE-2021-20649MEDIUM

ELECOM WRC-300FEBK-S contains an improper certificate validation vulnerability. Via a man-in-the-middle attack, an attacker may alter the communication response. As a result, an arbitrary OS command may be executed on the affected device.

12 Feb 2021
4.8
CVSS
CVE-2021-20648MEDIUM

ELECOM WRC-300FEBK-S allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.

12 Feb 2021
6.8
CVSS
CVE-2021-20647MEDIUM

Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-S allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be started.

12 Feb 2021
6.5
CVSS
CVE-2021-20646MEDIUM

Cross-site request forgery (CSRF) vulnerability in ELECOM WRC-300FEBK-A allows remote attackers to hijack the authentication of administrators and execute an arbitrary request via unspecified vector. As a result, the device settings may be altered and/or telnet daemon may be started.

12 Feb 2021
6.5
CVSS
CVE-2021-20645MEDIUM

Cross-site scripting vulnerability in ELECOM WRC-300FEBK-A allows remote authenticated attackers to inject arbitrary script via unspecified vectors.

12 Feb 2021
5.4
CVSS
CVE-2021-20644MEDIUM

ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web setup page.

12 Feb 2021
6.1
CVSS
CVE-2021-20643HIGH

Improper access control vulnerability in ELECOM LD-PS/U1 allows remote attackers to change the administrative password of the affected device by processing a specially crafted request.

12 Feb 2021
7.5
CVSS
CVE-2020-5634HIGH

ELECOM LAN routers (WRC-2533GST2 firmware versions prior to v1.14, WRC-1900GST2 firmware versions prior to v1.14, WRC-1750GST2 firmware versions prior to v1.14, and WRC-1167GST2 firmware versions prior to v1.10) allow an attacker on the same network segment to execute arbitrary OS commands with a root privilege via unspecified vectors.

6 Oct 2020
8.8
CVSS
← PrevPage 2 / 2Next →
Elecom CVEs & Vulnerabilities — 63 Tracked — Page 2