Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Elecom

First CVE: Oct 6, 2020Active for: 6 yearsTotal CVEs: 63
27.6
VTI Score
Low

Elecom manufactures a broad line of consumer and small-business networking devices, particularly wireless routers and related connectivity appliances, many of which remain deployed across residential and office environments for extended periods. Vulnerabilities affecting the vendor skew toward serious outcomes, with a meaningful share reaching critical severity, and recur across product families such as the WRC router line through weakness classes including OS command injection, cross-site scripting, code injection, and CSRF that are characteristic of embedded network management interfaces. The combination of internet-facing management surfaces, often accessible with default or weak credentials, and the long operational lifetime of networking hardware means that even unpatched flaws retain risk over time. Defenders should inventory affected Elecom devices and restrict administrative access through network segmentation or firewall controls; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
63
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.5
Avg CVSS Score
Higher Avg CVSS Score than 57% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Elecom over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 6, 2020
5 years ago
Most Recent CVE
Feb 3, 2026
171 days ago

Products(256 total)

Top CVEs

Signals from CVEs in this vendor scope (63 CVEs).

63 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-22550HIGH
OS command injection vulnerability exists in ELECOM wireless LAN products. A crafted request from a logged-in user may lead to an arbitrary OS command execution.
Feb 3, 20268.833NONO
CVE-2023-32626CRITICAL
Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the product's certain management con
Aug 18, 20239.830NONO
CVE-2026-24465CRITICAL
Stack-based buffer overflow vulnerability exists in ELECOM wireless LAN access point devices. A crafted packet may lead to arbitrary code execution.
Feb 3, 20269.828NONO
CVE-2024-43689CRITICAL
Stack-based buffer overflow vulnerability exists in ELECOM wireless access points. By processing a specially crafted HTTP request, arbitrary code may be executed.
Oct 21, 20249.827NONO
CVE-2023-35991CRITICAL
Hidden functionality vulnerability in LOGITEC wireless LAN routers allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS
Aug 18, 20239.827NONO
CVE-2022-25915HIGH
Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior,
Mar 31, 20228.827NONO
CVE-2022-21173HIGH
Hidden functionality vulnerability in ELECOM LAN routers (WRH-300BK3 firmware v1.05 and earlier, WRH-300WH3 firmware v1.05 and earlier, WRH-300BK3-S firmware v1.05 and earlier, WRH
Feb 8, 20228.827NONO
CVE-2021-20864HIGH
Improper access control vulnerability in ELECOM routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior, WRC-
Dec 1, 20218.827NONO
CVE-2021-20861HIGH
Improper access control vulnerability in ELECOM LAN routers (WRC-1167GST2 firmware v1.25 and prior, WRC-1167GST2A firmware v1.25 and prior, WRC-1167GST2H firmware v1.25 and prior,
Dec 1, 20218.827NONO
CVE-2021-20739HIGH
WRC-300FEBK, WRC-F300NF, WRC-733FEBK, WRH-300RD, WRH-300BK, WRH-300SV, WRH-300WH, WRH-H300WH, WRH-H300BK, WRH-300BK-S, and WRH-300WH-S all versions allows an unauthenticated networ
Jul 7, 20218.827NONO
View all 63 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products63 CVEs
43%
43%
13%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (3.2%)
Network33 (52.4%)
Unknown0 (0.0%)
Physical1 (1.6%)
Adjacent Network27 (42.9%)
Attack Complexity
Low61 (96.8%)
High2 (3.2%)
Unknown0 (0.0%)
User Interaction
None42 (66.7%)
Unknown0 (0.0%)
Required21 (33.3%)
Privileges Required
Low18 (28.6%)
High7 (11.1%)
None38 (60.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (63 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Elecom.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Elecom — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Elecom's Products

View all 1 CNAs →

Top CWEs