Description
ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file.
Published: 2026-05-13
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ELECOM wireless LAN access points use a fixed cryptographic key when creating backup configuration files. An attacker who discovers this key can modify the backup file, after which the compromised configuration may be loaded by an administrator. The result is unauthorized changes to network settings, potentially exposing the network or enabling further malicious activity. The flaw affects the integrity of critical device configuration data.

Affected Systems

Affected devices include ELECOM wireless LAN access points: WRC‑X1800GS‑B, WRC‑X1800GSA‑B, WRC‑X1800GSH‑B, WRC‑X3000GS2‑B, WRC‑X3000GS2‑W, WRC‑X3000GS2A‑B, WRC‑X3000GST2‑B, WRC‑X6000QS‑G, WRC‑X6000QSA‑G, WRC‑X6000XS‑G, WRC‑X6000XST‑G, WRC‑XE5400GS‑G, and WRC‑XE5400GSA‑G. No specific firmware or revision numbers are provided, so all models using the described backup feature are potentially vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate to high severity. EPSS data is currently unavailable, and the vulnerability is not listed in the CISA KEV catalog. The attack path requires an attacker to obtain the hard‑coded key, which could be derived through firmware reverse engineering or other means. With the key in hand, the attacker can tamper the configuration file and potentially have an administrator unknowingly apply it, leading to persistent misconfiguration of the network device.

Generated by OpenCVE AI on May 13, 2026 at 14:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain the Elecom firmware update that removes the hard‑coded key or implements secure key management for backups
  • Deploy the updated firmware to all affected WRC‑X1800GS‑B, WRC‑X1800GSA‑B, WRC‑X1800GSH‑B, WRC‑X3000GS2‑B, WRC‑X3000GS2‑W, WRC‑X3000GS2A‑B, WRC‑X3000GST2‑B, WRC‑X6000QS‑G, WRC‑X6000QSA‑G, WRC‑X6000XS‑G, WRC‑X6000XST‑G, WRC‑XE5400GS‑G, and WRC‑XE5400GSA‑G
  • After installing the update, verify that backup creation and restoration use per‑device unique keys or secure encryption and consider disabling automated backup functions until the patch is fully deployed

Generated by OpenCVE AI on May 13, 2026 at 14:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 17 May 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Elecom
Elecom wrc-x1800gs-b
Elecom wrc-x1800gsa-b
Elecom wrc-x1800gsh-b
Elecom wrc-x3000gs2-b
Elecom wrc-x3000gs2-w
Elecom wrc-x3000gs2a-b
Elecom wrc-x6000qs-g
Elecom wrc-x6000qsa-g
Elecom wrc-x6000xs-g
Elecom wrc-x6000xst-g
Elecom wrc-xe5400gs-g
Elecom wrc-xe5400gsa-g
Vendors & Products Elecom
Elecom wrc-x1800gs-b
Elecom wrc-x1800gsa-b
Elecom wrc-x1800gsh-b
Elecom wrc-x3000gs2-b
Elecom wrc-x3000gs2-w
Elecom wrc-x3000gs2a-b
Elecom wrc-x6000qs-g
Elecom wrc-x6000qsa-g
Elecom wrc-x6000xs-g
Elecom wrc-x6000xst-g
Elecom wrc-xe5400gs-g
Elecom wrc-xe5400gsa-g

Wed, 13 May 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 May 2026 12:45:00 +0000

Type Values Removed Values Added
Description ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of the product, and a victim administrator may be tricked to use a crafted configuration file.
Weaknesses CWE-321
References
Metrics cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Elecom Wrc-x1800gs-b Wrc-x1800gsa-b Wrc-x1800gsh-b Wrc-x3000gs2-b Wrc-x3000gs2-w Wrc-x3000gs2a-b Wrc-x6000qs-g Wrc-x6000qsa-g Wrc-x6000xs-g Wrc-x6000xst-g Wrc-xe5400gs-g Wrc-xe5400gsa-g
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-05-13T18:26:26.218Z

Reserved: 2026-05-07T05:47:06.075Z

Link: CVE-2026-25107

cve-icon Vulnrichment

Updated: 2026-05-13T18:26:22.969Z

cve-icon NVD

Status : Deferred

Published: 2026-05-13T13:16:37.160

Modified: 2026-05-13T15:47:10.327

Link: CVE-2026-25107

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-17T19:42:05Z

Weaknesses