CVE-2025-41427: Elecom Co.,ltd Wrc-x3000gs
High severity, CVSS 8.7. EPSS: 1% chance of exploitation in the next 30 days.
WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Connection Diagnostics page. If a remote authenticated attacker sends a specially crafted request to the affected product, an arbitrary OS command may be executed.
Affected products
- Elecom Co.,ltd Wrc-x3000gs: up to and including v1.0.34
- Elecom Co.,ltd Wrc-x3000gsa: up to and including v1.0.34
- Elecom Co.,ltd Wrc-x3000gsn: up to and including v1.0.9
Published 2025-06-24. Last modified 2026-06-17.