Back to Database
Status published
Unknown
CVE-2023-40072
OS command injection vulnerability in ELECOM wireless LAN access point...
Vulnerability Description
OS command injection vulnerability in ELECOM wireless LAN access point devices allows an authenticated user to execute an arbitrary OS command by sending a specially crafted request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-40072
Credits & Attribution
No credits recorded in the NVD database.
References
More from ELECOM CO.,LTD.
View All →CVE-2025-66271
Clone for Windows provided by ELECOM CO.,LTD. registers a Windows...
High
8.4
CVE-2025-53472
WRC-BE36QS-B and WRC-W701-B contain an improper neutralization of special elements...
High
8.6
CVE-2025-48890
WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements...
Critical
9.3
CVE-2025-46267
Hidden functionality issue exists in WRC-BE36QS-B and WRC-W701-B. If exploited,...
Medium
6.9
CVE-2025-43879
WRH-733GBK and WRH-733GWH contain an improper neutralization of special elements...
Critical
9.3
Affected Vendor
ELECOM CO.,LTD.
View all reports →Affected Software
WAB-S600-PS, WAB-S300, WAB-S1775, WAB-M1775-PS, WAB-S1167, WAB-M2133, WAB-I1750-PS, WAB-S1167-PS
Vulnerable Versions:
all versions, v1.1.9 and earlier, v1.1.21 and earlier, v1.0.7 and earlier, v1.3.22 and earlier, v1.5.10 and earlier, v1.5.6 and earlier
Timeline
Official Publish:
August 18th, 2023
Last Modified:
July 3rd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.