CVE-2026-22550

OS command injection vulnerability exists in WRC-X1500GS-B and WRC-X1500GSA-B. A crafted request from a logged-in user may lead to an arbitrary OS command execution.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:elecom:wrc-x1500gsa-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1500gsa-b:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:elecom:wrc-x1500gs-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1500gs-b:-:*:*:*:*:*:*:*

History

10 Apr 2026, 14:35

Type Values Removed Values Added
CPE cpe:2.3:o:elecom:wrc-x1500gsa-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:elecom:wrc-x1500gs-b_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1500gs-b:-:*:*:*:*:*:*:*
cpe:2.3:h:elecom:wrc-x1500gsa-b:-:*:*:*:*:*:*:*
References () https://jvn.jp/en/jp/JVN94012927/ - () https://jvn.jp/en/jp/JVN94012927/ - Third Party Advisory
References () https://www.elecom.co.jp/news/security/20260203-01/ - () https://www.elecom.co.jp/news/security/20260203-01/ - Vendor Advisory
Summary
  • (es) Existe una vulnerabilidad de inyección de comandos del sistema operativo en WRC-X1500GS-B y WRC-X1500GSA-B. Una solicitud manipulada de un usuario autenticado puede conducir a la ejecución arbitraria de comandos del sistema operativo.
First Time Elecom wrc-x1500gsa-b Firmware
Elecom wrc-x1500gsa-b
Elecom wrc-x1500gs-b
Elecom
Elecom wrc-x1500gs-b Firmware
CVSS v2 : unknown
v3 : 7.2
v2 : unknown
v3 : 8.8

03 Feb 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 07:16

Updated : 2026-04-10 14:35


NVD link : CVE-2026-22550

Mitre link : CVE-2026-22550

CVE.ORG link : CVE-2026-22550


JSON object : View

Products Affected

elecom

  • wrc-x1500gsa-b_firmware
  • wrc-x1500gs-b_firmware
  • wrc-x1500gs-b
  • wrc-x1500gsa-b
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')