CVE-2024-23910: Elecom Wmc-x1800gst-B Firmware

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators and to perform unintended operations to the affected product. Note that WMC-X1800GST-B and WSC-X1800GS-B are also included in e-Mesh Starter Kit "WMC-2LX-B".

Affected products

  • Elecom Wmc-x1800gst-B Firmware: before 1.42 (fixed in 1.42)
  • Elecom Wrc-1167gs2-B Firmware: before 1.73 (fixed in 1.73)
  • Elecom Wrc-1167gs2h-B Firmware: before 1.73 (fixed in 1.73)
  • Elecom Wrc-1167gst2 Firmware: before 1.34 (fixed in 1.34)
  • Elecom Wrc-2533gs2-B Firmware: before 1.68 (fixed in 1.68)
  • Elecom Wrc-2533gs2-W Firmware: before 1.68 (fixed in 1.68)
  • Elecom Wrc-2533gs2v-B Firmware: before 1.68 (fixed in 1.68)
  • Elecom Wrc-2533gst2 Firmware: before 1.31 (fixed in 1.31)
  • Elecom Wrc-g01-W Firmware: before 1.26 (fixed in 1.26)
  • Elecom Wrc-x3200gst3-B Firmware: before 1.27 (fixed in 1.27)
  • Elecom Wsc-x1800gs-B Firmware: before 1.42 (fixed in 1.42)

Published 2024-02-28. Last modified 2026-06-17.