CVE-2023-40072: Elecom Wab-s300 Firmware

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

OS command injection vulnerability in ELECOM wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command by sending a specially crafted request.

Affected products

  • Elecom Wab-s300 Firmware: any version
  • Elecom Wab-s600-Ps Firmware: any version

Published 2023-08-18. Last modified 2026-06-17.