CVE-2026-25107
CVE-2026-25107
ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
ELECOM CO.,LTD. · WRC-X1800GSA-BELECOM CO.,LTD. · WRC-X1800GS-BELECOM CO.,LTD. · WRC-X1800GSH-BELECOM CO.,LTD. · WRC-X3000GS2A-BELECOM CO.,LTD. · WRC-X3000GS2-BELECOM CO.,LTD. · WRC-X3000GS2-WELECOM CO.,LTD. · WRC-X3000GST2-BELECOM CO.,LTD. · WRC-X6000QSA-GELECOM CO.,LTD. · WRC-X6000QS-GELECOM CO.,LTD. · WRC-X6000XS-GELECOM CO.,LTD. · WRC-X6000XST-GELECOM CO.,LTD. · WRC-XE5400GSA-GELECOM CO.,LTD. · WRC-XE5400GS-G¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →