CVE-2023-49695: Elecom Wrc-x3000gs Firmware
Medium severity, CVSS 6.8. EPSS: 0.9% chance of exploitation in the next 30 days.
OS command injection vulnerability in WRC-X3000GSN v1.0.2, WRC-X3000GS v1.0.24 and earlier, and WRC-X3000GSA v1.0.24 and earlier allows a network-adjacent attacker with an administrative privilege to execute an arbitrary OS command by sending a specially crafted request to the product.
Affected products
- Elecom Wrc-x3000gs Firmware: up to and including 1.0.24
- Elecom Wrc-x3000gsa Firmware: up to and including 1.0.24
- Elecom Wrc-x3000gsn Firmware: version 1.0.2 only
Published 2023-12-12. Last modified 2026-06-17.