CVE-2025-36519: Elecom Co.,ltd Wrc-1167gs2-B
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Unrestricted upload of file with dangerous type issue exists in WRC-2533GST2, WRC-1167GST2, WRC-2533GST2, WRC-2533GS2V-B,WRC-2533GS2-B v1.69 and earlier, WRC-2533GS2-W, WRC-1167GST2, WRC-1167GS2-B, and WRC-1167GS2H-B. If a specially crafted file is uploaded by a remote authenticated attacker, arbitrary code may be executed on the product.
Affected products
- Elecom Co.,ltd Wrc-1167gs2-B: up to and including v1.74
- Elecom Co.,ltd Wrc-1167gs2h-B: up to and including v1.74
- Elecom Co.,ltd Wrc-1167gst2: up to and including v1.34
- Elecom Co.,ltd Wrc-2533gs2-B: up to and including v1.69
- Elecom Co.,ltd Wrc-2533gs2-W: up to and including v1.69
- Elecom Co.,ltd Wrc-2533gs2v-B: up to and including v1.69
- Elecom Co.,ltd Wrc-2533gst2: up to and including v1.31
Published 2025-06-24. Last modified 2026-06-17.