CVE-2023-40069

CRITICAL

ELECOM Wireless LAN Routers - OS Command Injection

Title source: llm
STIX 2.1

Description

OS command injection vulnerability in ELECOM wireless LAN routers allows an attacker who can access the product to execute an arbitrary OS command by sending a specially crafted request. Affected products and versions are as follows: WRC-F1167ACF all versions, WRC-1750GHBK all versions, WRC-1167GHBK2 all versions, WRC-1750GHBK2-I all versions, and WRC-1750GHBK-E all versions.

References (2)

Core 2

Scores

CVSS v3 9.8
EPSS 0.0124
EPSS Percentile 65.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (5)
elecom/wrc-1167ghbk2_firmware
elecom/wrc-1750ghbk-e_firmware
elecom/wrc-1750ghbk2-i_firmware
elecom/wrc-1750ghbk_firmware
elecom/wrc-f1167acf_firmware
Published Aug 18, 2023
Tracked Since Feb 18, 2026