elecom records
69 published records for vendor elecom.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 14
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')20
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')10
- CWE-352 Cross-Site Request Forgery (CSRF)7
- CWE-94 Improper Control of Generation of Code ('Code Injection')4
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')3
- CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
69 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2023-37567No exploit | Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary elecom · wrc-1167ghbk3-a firmware · CWE-77 | Critical9.8 | — | 2.4% | Jul 12, 2023 |
39Monitor | CVE-2023-40069No exploit | OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS celecom · wrc-f1167acf firmware · CWE-78 | Critical9.8 | — | 1.5% | Aug 18, 2023 |
39Monitor | CVE-2023-39454No exploit | Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code.elecom · wrc-x1800gs-b firmware · CWE-120 | Critical9.8 | — | 0.9% | Aug 18, 2023 |
39Monitor | CVE-2024-43689No exploit | Stack-based buffer overflow vulnerability exists in ELECOM wireless access points.elecom · wab-i1750-ps firmware · CWE-121 | Critical9.8 | — | 0.9% | Oct 20, 2024 |
39Monitor | CVE-2023-32626No exploit | Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log inelecom · lan-w300n\/rs firmware · CWE-94 | Critical9.8 | — | 0.8% | Aug 18, 2023 |
39Monitor | CVE-2023-35991No exploit | Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain manelecom · lan-wh300andgpe firmware | Critical9.8 | — | 0.7% | Aug 18, 2023 |
37Monitor | CVE-2021-20651No exploit | Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary file or overwrite an exelecom · file manager · CWE-22 | Critical9.1 | — | 1.9% | Feb 12, 2021 |
37Monitor | CVE-2026-24465No exploit | Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices.elecom · wab-s300iw-pd firmware · CWE-121 | Critical9.3 | — | 0.7% | Feb 3, 2026 |
36Monitor | CVE-2023-40072No exploit | OS command injection vulnerability in ELECOM wireless LAN access point devices allows an authenticated user to execute an arbitrary OS commaelecom · wab-s600-ps firmware · CWE-78 | High8.8 | — | 1.9% | Aug 18, 2023 |
35Monitor | CVE-2026-22550No exploit | OS command injection vulnerability exists in ELECOM wireless LAN products.elecom · wrc-x1500gsa-b firmware · CWE-78 | High8.6 | — | 1.8% | Feb 3, 2026 |
35Monitor | CVE-2023-39455No exploit | OS command injection vulnerability in ELECOM wireless LAN routers allows an authenticated user to execute an arbitrary OS command by sendingelecom · wrc-600ghbk-a firmware · CWE-78 | High8.8 | — | 1.5% | Aug 18, 2023 |
35Monitor | CVE-2023-39944No exploit | OS command injection vulnerability in WRC-F1167ACF all versions, and WRC-1750GHBK all versions allows an attacker who can access the productelecom · wrc-f1167acf firmware · CWE-78 | High8.8 | — | 1.5% | Aug 18, 2023 |
35Monitor | CVE-2024-25568No exploit | OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent unauthenticated attacker to execute arbitrary OSelecom co.,ltd. · wrc-x3200gst3-b · CWE-78 | High8.8 | — | 1.1% | Apr 3, 2024 |
35Monitor | CVE-2020-5634No exploit | ELECOM LAN routers (WRC-2533GST2 firmware versions prior to v1.14, WRC-1900GST2 firmware versions prior to v1.14, WRC-1750GST2 firmware verselecom · wrc-2533gst2 firmware | High8.8 | — | 0.6% | Oct 6, 2020 |
35Monitor | CVE-2023-39445No exploit | Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an unauthenticated attacker to execuelecom · wrc-1467ghbk-a firmware · CWE-94 | High8.8 | — | 0.6% | Aug 18, 2023 |
35Monitor | CVE-2021-20860No exploit | Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 aelecom · wrc-1167gst2 firmware · CWE-352 | High8.8 | — | 0.6% | Nov 30, 2021 |
35Monitor | CVE-2021-20864No exploit | Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-elecom · wrc-1167gst2 firmware | High8.8 | — | 0.5% | Nov 30, 2021 |
35Monitor | CVE-2021-20739No exploit | WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all velecom · wrc-300febk firmware · CWE-78 | High8.8 | — | 0.5% | Jul 7, 2021 |
35Monitor | CVE-2021-20861No exploit | Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, elecom · wrc-1167gst2 firmware | High8.8 | — | 0.5% | Nov 30, 2021 |
35Monitor | CVE-2022-21173No exploit | Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-elecom · wrh-300bk3 firmware | High8.8 | — | 0.4% | Feb 8, 2022 |
35Monitor | CVE-2022-25915No exploit | Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, elecom · wrc-1167gst2 firmware | High8.8 | — | 0.4% | Mar 31, 2022 |
35Monitor | CVE-2023-38132No exploit | LAN-W451NGR all versions provided by LOGITEC CORPORATION contains an improper access control vulnerability, which allows an unauthenticated elecom · lan-w451ngr firmware · CWE-284 | High8.8 | — | 0.3% | Aug 18, 2023 |
35Monitor | CVE-2023-37562No exploit | Cross-site request forgery (CSRF) vulnerability in exists in WTC-C1167GC-B v1.17 and earlier, and WTC-C1167GC-W v1.17 and earlier.elecom · wtc-c1167gc-b firmware · CWE-352 | High8.8 | — | 0.3% | Jul 12, 2023 |
35Monitor | CVE-2024-23910No exploit | Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attelecom · wrc-1167gs2-b firmware · CWE-352 | High8.8 | — | 0.2% | Feb 28, 2024 |
35Monitor | CVE-2024-40883No exploit | Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers.elecom · wrc-2533gs2-b firmware · CWE-352 | High8.8 | — | 0.2% | Jul 31, 2024 |
- CVE-2023-3756740Plan
Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary
CriticalCVSS 9.8No exploitEPSS 2%elecom · wrc-1167ghbk3-a firmwareJul 12, 2023
- CVE-2023-4006939Monitor
OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS c
CriticalCVSS 9.8No exploitEPSS 1%elecom · wrc-f1167acf firmwareAug 18, 2023
- CVE-2023-3945439Monitor
Buffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code.
CriticalCVSS 9.8No exploitEPSS 1%elecom · wrc-x1800gs-b firmwareAug 18, 2023
- CVE-2024-4368939Monitor
Stack-based buffer overflow vulnerability exists in ELECOM wireless access points.
CriticalCVSS 9.8No exploitEPSS 1%elecom · wab-i1750-ps firmwareOct 20, 2024
- CVE-2023-3262639Monitor
Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in
CriticalCVSS 9.8No exploitEPSS 1%elecom · lan-w300n\/rs firmwareAug 18, 2023
- CVE-2023-3599139Monitor
Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain man
CriticalCVSS 9.8No exploitEPSS 1%elecom · lan-wh300andgpe firmwareAug 18, 2023
- CVE-2021-2065137Monitor
Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary file or overwrite an ex
CriticalCVSS 9.1No exploitEPSS 2%elecom · file managerFeb 12, 2021
- CVE-2026-2446537Monitor
Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices.
CriticalCVSS 9.3No exploitEPSS 1%elecom · wab-s300iw-pd firmwareFeb 3, 2026
- CVE-2023-4007236Monitor
OS command injection vulnerability in ELECOM wireless LAN access point devices allows an authenticated user to execute an arbitrary OS comma
HighCVSS 8.8No exploitEPSS 2%elecom · wab-s600-ps firmwareAug 18, 2023
- CVE-2026-2255035Monitor
OS command injection vulnerability exists in ELECOM wireless LAN products.
HighCVSS 8.6No exploitEPSS 2%elecom · wrc-x1500gsa-b firmwareFeb 3, 2026
- CVE-2023-3945535Monitor
OS command injection vulnerability in ELECOM wireless LAN routers allows an authenticated user to execute an arbitrary OS command by sending
HighCVSS 8.8No exploitEPSS 1%elecom · wrc-600ghbk-a firmwareAug 18, 2023
- CVE-2023-3994435Monitor
OS command injection vulnerability in WRC-F1167ACF all versions, and WRC-1750GHBK all versions allows an attacker who can access the product
HighCVSS 8.8No exploitEPSS 1%elecom · wrc-f1167acf firmwareAug 18, 2023
- CVE-2024-2556835Monitor
OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent unauthenticated attacker to execute arbitrary OS
HighCVSS 8.8No exploitEPSS 1%elecom co.,ltd. · wrc-x3200gst3-bApr 3, 2024
- CVE-2020-563435Monitor
ELECOM LAN routers (WRC-2533GST2 firmware versions prior to v1.14, WRC-1900GST2 firmware versions prior to v1.14, WRC-1750GST2 firmware vers
HighCVSS 8.8No exploitEPSS 1%elecom · wrc-2533gst2 firmwareOct 6, 2020
- CVE-2023-3944535Monitor
Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an unauthenticated attacker to execu
HighCVSS 8.8No exploitEPSS 1%elecom · wrc-1467ghbk-a firmwareAug 18, 2023
- CVE-2021-2086035Monitor
Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 a
HighCVSS 8.8No exploitEPSS 1%elecom · wrc-1167gst2 firmwareNov 30, 2021
- CVE-2021-2086435Monitor
Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-
HighCVSS 8.8No exploitEPSS 1%elecom · wrc-1167gst2 firmwareNov 30, 2021
- CVE-2021-2073935Monitor
WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all v
HighCVSS 8.8No exploitEPSS 1%elecom · wrc-300febk firmwareJul 7, 2021
- CVE-2021-2086135Monitor
Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior,
HighCVSS 8.8No exploitEPSS 0%elecom · wrc-1167gst2 firmwareNov 30, 2021
- CVE-2022-2117335Monitor
Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-
HighCVSS 8.8No exploitEPSS 0%elecom · wrh-300bk3 firmwareFeb 8, 2022
- CVE-2022-2591535Monitor
Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior,
HighCVSS 8.8No exploitEPSS 0%elecom · wrc-1167gst2 firmwareMar 31, 2022
- CVE-2023-3813235Monitor
LAN-W451NGR all versions provided by LOGITEC CORPORATION contains an improper access control vulnerability, which allows an unauthenticated
HighCVSS 8.8No exploitEPSS 0%elecom · lan-w451ngr firmwareAug 18, 2023
- CVE-2023-3756235Monitor
Cross-site request forgery (CSRF) vulnerability in exists in WTC-C1167GC-B v1.17 and earlier, and WTC-C1167GC-W v1.17 and earlier.
HighCVSS 8.8No exploitEPSS 0%elecom · wtc-c1167gc-b firmwareJul 12, 2023
- CVE-2024-2391035Monitor
Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated att
HighCVSS 8.8No exploitEPSS 0%elecom · wrc-1167gs2-b firmwareFeb 28, 2024
- CVE-2024-4088335Monitor
Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers.
HighCVSS 8.8No exploitEPSS 0%elecom · wrc-2533gs2-b firmwareJul 31, 2024