Vulnerabilidades em ELECOM CO.,LTD.

84 resultados
Análise Vexday

Com 81 CVEs catalogadas e nenhuma confirmação de exploração ativa no catálogo KEV da CISA, o perfil de risco imediato dos produtos ELECOM CO.,LTD. situa-se abaixo da média geral do catálogo. A falha mais comum é CWE-78 (OS Command Injection), categoria que historicamente oferece primitivas de execução remota de comandos e merece atenção prioritária em ambientes expostos à rede. Das 81 vulnerabilidades, 6 são classificadas como críticas e 7 surgiram nos últimos 90 dias, indicando ritmo contínuo de descoberta; a CVE mais perigosa atualmente rastreada é CVE-2025-43879, com EPSS de 0,0263, o que sugere probabilidade ainda moderada de exploração em curto prazo. A ausência de PoCs públicas conhecidas reduz a exposição imediata, mas não elimina o risco, especialmente dado o padrão de injeção de comandos prevalente no portfólio.

CVE-2024-43689HIGHStack-based buffer overflow vulnerability exists in ELECOM wireless access points. By processing a specially crafted HTTP request, arbitraryEPSS 0.9%CVE-2023-37564OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute an arbitrary OEPSS 0.9%CVE-2023-49695MEDIUMOS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a neEPSS 0.9%CVE-2023-39454HIGHBuffer overflow vulnerability exists in ELECOM wireless LAN routers, which may allow an unauthenticated attacker to execute arbitrary code.EPSS 0.9%CVE-2021-20863OS command injection vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-116EPSS 0.9%CVE-2024-39607MEDIUMOS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product byEPSS 0.9%CVE-2024-25579MEDIUMOS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to exeEPSS 0.8%CVE-2024-22372MEDIUMOS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to exeEPSS 0.8%CVE-2026-24465CRITICALStack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead to arbitrary code exEPSS 0.7%CVE-2021-20645Cross-site scripting vulnerability in ELECOM WRC-300FEBK-A allows remote authenticated attackers to inject arbitrary script via unspecified EPSS 0.7%CVE-2024-36103MEDIUMOS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a network-adjacent atEPSS 0.7%CVE-2024-26258HIGHOS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with credentials to execute arbitrary OEPSS 0.7%CVE-2020-5634ELECOM LAN routers (WRC-2533GST2 firmware versions prior to v1.14, WRC-1900GST2 firmware versions prior to v1.14, WRC-1750GST2 firmware versEPSS 0.6%CVE-2021-20644ELECOM WRC-1467GHBK-A allows arbitrary scripts to be executed on the user's web browser by displaying a specially crafted SSID on the web seEPSS 0.6%CVE-2021-20856Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) aEPSS 0.6%CVE-2021-20857Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenticated attacker to inEPSS 0.6%CVE-2021-20855Cross-site scripting vulnerability in ELECOM LAN routers (WRH-733GBK firmware v1.02.9 and prior and WRH-733GWH firmware v1.02.9 and prior) aEPSS 0.6%CVE-2021-20858Cross-site scripting vulnerability in ELECOM LAN router WRC-2533GHBK-I firmware v1.20 and prior allows a remote authenticated attacker to inEPSS 0.6%CVE-2021-20859ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WEPSS 0.5%CVE-2021-20860Cross-site request forgery (CSRF) vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 aEPSS 0.5%