CVE-2024-10118: Secom Wrtr-304gn-304tw-Upsc

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

SECOM WRTR-304GN-304TW-UPSC does not properly filter user input in the specific functionality. Unauthenticated remote attackers can exploit this vulnerability to inject and execute arbitrary system commands on the device.

Affected products

  • Secom Wrtr-304gn-304tw-Upsc: version 0 only
  • Secom Wrtr-304gn-304tw-Upsc Firmware: version v02 only

Published 2024-10-18. Last modified 2026-06-17.