CVE-2024-22372: Elecom Wrc-x1800gs-B Firmware

Medium severity, CVSS 6.8. EPSS: 0.8% chance of exploitation in the next 30 days.

OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to the product.

Affected products

  • Elecom Wrc-x1800gs-B Firmware: before 1.18 (fixed in 1.18)
  • Elecom Wrc-x1800gsa-B Firmware: before 1.18 (fixed in 1.18)
  • Elecom Wrc-x1800gsh-B Firmware: before 1.18 (fixed in 1.18)
  • Elecom Wrc-x6000xs-G Firmware: version 1.09 only
  • Elecom Wrc-x6000xst-G Firmware: before 1.14 (fixed in 1.14)

Published 2024-01-24. Last modified 2026-06-17.