CVE-2026-22550: Elecom Wrc-x1500gs-B Firmware

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command execution.

Affected products

  • Elecom Wrc-x1500gs-B Firmware: up to and including 1.13
  • Elecom Wrc-x1500gsa-B Firmware: up to and including 1.13

Published 2026-02-03. Last modified 2026-06-17.