Vulnerability Description
OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Elecom | Wrc-X1500Gsa-B Firmware | <= 1.13 |
| Elecom | Wrc-X1500Gsa-B | - |
| Elecom | Wrc-X1500Gs-B Firmware | <= 1.13 |
| Elecom | Wrc-X1500Gs-B | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN94012927/Third Party Advisory
- https://www.elecom.co.jp/news/security/20260203-01/Vendor Advisory
FAQ
What is CVE-2026-22550?
CVE-2026-22550 is a vulnerability with a CVSS score of 8.8 (HIGH). OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command execution.
How severe is CVE-2026-22550?
CVE-2026-22550 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-22550?
Check the references section above for vendor advisories and patch information. Affected products include: Elecom Wrc-X1500Gsa-B Firmware, Elecom Wrc-X1500Gsa-B, Elecom Wrc-X1500Gs-B Firmware, Elecom Wrc-X1500Gs-B.