CVE-2024-40883: Elecom Wrc-2533gs2-B Firmware

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging in to the affected product with an administrative privilege, the user may be directed to perform unintended operations such as changing the login ID, login password, etc.

Affected products

  • Elecom Wrc-2533gs2-B Firmware: before 1.69 (fixed in 1.69)
  • Elecom Wrc-2533gs2-W Firmware: before 1.69 (fixed in 1.69)
  • Elecom Wrc-2533gs2v-B Firmware: before 1.69 (fixed in 1.69)
  • Elecom Wrc-x1500gs-B Firmware: before 1.12 (fixed in 1.12)
  • Elecom Wrc-x1500gsa-B Firmware: before 1.12 (fixed in 1.12)
  • Elecom Wrc-x6000xs-G Firmware: before 1.12 (fixed in 1.12)

Published 2024-08-01. Last modified 2026-06-17.