Vulnerabilidades em ELECOM CO.,LTD.

84 resultados
Análise Vexday

Com 81 CVEs catalogadas e nenhuma confirmação de exploração ativa no catálogo KEV da CISA, o perfil de risco imediato dos produtos ELECOM CO.,LTD. situa-se abaixo da média geral do catálogo. A falha mais comum é CWE-78 (OS Command Injection), categoria que historicamente oferece primitivas de execução remota de comandos e merece atenção prioritária em ambientes expostos à rede. Das 81 vulnerabilidades, 6 são classificadas como críticas e 7 surgiram nos últimos 90 dias, indicando ritmo contínuo de descoberta; a CVE mais perigosa atualmente rastreada é CVE-2025-43879, com EPSS de 0,0263, o que sugere probabilidade ainda moderada de exploração em curto prazo. A ausência de PoCs públicas conhecidas reduz a exposição imediata, mas não elimina o risco, especialmente dado o padrão de injeção de comandos prevalente no portfólio.

CVE-2023-37567Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a remote unauthenticated attacker to execute an arbitrary EPSS 2.4%CVE-2025-48890CRITICALWRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilitEPSS 2.2%CVE-2025-43879CRITICALWRH-733GBK and WRH-733GWH contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilitEPSS 2.2%CVE-2021-20651Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary file or overwrite an exEPSS 1.9%CVE-2026-22550HIGHOS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary EPSS 1.7%CVE-2026-42062CRITICALELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted requesEPSS 1.6%CVE-2023-40072HIGHOS command injection vulnerability in ELECOM wireless LAN access point devices allows an authenticated user to execute an arbitrary OS commaEPSS 1.6%CVE-2026-35506HIGHELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processinEPSS 1.3%CVE-2024-21798MEDIUMELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affecteEPSS 1.3%CVE-2023-39455OS command injection vulnerability in ELECOM wireless LAN routers allows an authenticated user to execute an arbitrary OS command by sendingEPSS 1.3%CVE-2023-40069CRITICALOS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS cEPSS 1.2%CVE-2023-39944OS command injection vulnerability in WRC-F1167ACF all versions, and WRC-1750GHBK all versions allows an attacker who can access the productEPSS 1.2%CVE-2021-20643Improper access control vulnerability in ELECOM LD-PS/U1 allows remote attackers to change the administrative password of the affected devicEPSS 1.1%CVE-2024-25568HIGHOS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent unauthenticated attacker to execute arbitrary OSEPSS 1.1%CVE-2026-61376HIGHELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerabiliEPSS 1.1%CVE-2026-59764HIGHELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploEPSS 1.1%CVE-2023-37566Command injection vulnerability in ELECOM and LOGITEC wireless LAN routers allows a network-adjacent authenticated attacker to execute an arEPSS 1.1%CVE-2025-53472HIGHWRC-BE36QS-B and WRC-W701-B contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilEPSS 1.1%CVE-2023-43752OS command injection vulnerability in WRC-X3000GS2-W v1.05 and earlier, WRC-X3000GS2-B v1.05 and earlier, and WRC-X3000GS2A-B v1.05 and earlEPSS 1.0%CVE-2025-41427HIGHWRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command InjectEPSS 1.0%