CVE-2023-43752: Elecom Wrc-x3000gs2-B Firmware

High severity, CVSS 8.0. EPSS: 1% chance of exploitation in the next 30 days.

OS command injection vulnerability in WRC-X3000GS2-W v1.05 and earlier, WRC-X3000GS2-B v1.05 and earlier, and WRC-X3000GS2A-B v1.05 and earlier allows a network-adjacent authenticated user to execute an arbitrary OS command by sending a specially crafted request.

Affected products

  • Elecom Wrc-x3000gs2-B Firmware: up to and including 1.05
  • Elecom Wrc-x3000gs2-W Firmware: up to and including 1.05
  • Elecom Wrc-x3000gs2a-B Firmware: up to and including 1.05

Published 2023-11-16. Last modified 2026-06-17.