elecom-co-ltd
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting elecom-co-ltd.
- CVE-2026-61376ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed ...7.2
- CVE-2026-59764ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attac...7.2
- CVE-2026-44387ELECOM wireless LAN routers and access points devices contain a reflected cross-site scripting vulnerability in WebUI. If this vulnerability is exploited, an arbitrary script may be executed on a l...5.2
- CVE-2026-42961ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked ...4.3
- CVE-2026-42950ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may ...4.3
- CVE-2026-42948Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another admin...4.8
- CVE-2026-42062ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authentica...9.8
- CVE-2026-40621ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.9.8
- CVE-2026-35506ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrar...7.2
- CVE-2026-25107ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file ...6.5
- CVE-2026-24465Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead to arbitrary code execution.9.8
- CVE-2026-24449For WRC-X1500GS-B and WRC-X1500GSA-B, the initial passwords can be calculated easily from the system information.4.6
- CVE-2026-22550OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command execution.8.8
- CVE-2026-20704Cross-site request forgery vulnerability exists in ELECOM wireless LAN products. If a user accesses a malicious page while logged-in to the affected product, unintended operations may be performed.4.3
- CVE-2025-66271Clone for Windows provided by ELECOM CO.,LTD. registers a Windows service with an unquoted file path. A user with the write permission on the root directory of the system drive may execute arbitrar...6.7