CVE-2023-22282: Elecom Wab-Mat

High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.

WAB-MAT Ver.5.0.0.8 and earlier starts another program with an unquoted file path. Since a registered Windows service path contains spaces and are unquoted, if a malicious executable is placed on a certain path, the executable may be executed with the privilege of the Windows service.

Affected products

  • Elecom Wab-Mat: before 5.0.2.2 (fixed in 5.0.2.2)

Published 2023-04-11. Last modified 2026-06-17.