Impact
The vulnerability enables unauthenticated users to access specific URLs on Elecom wireless LAN access points. Because the device does not enforce authentication, an attacker can perform administrative functions such as configuration changes, firmware updates, or network traffic monitoring. The weakness is classified as CWE-288, highlighting a failure to enforce authentication controls, and effectively turns the device into a controllable target without authorization.
Affected Systems
Affected products are Elecom Co., Ltd. wireless LAN access points: WRC-BE65QSD-B, WRC-BE72XSD-B, WRC-BE72XSD-BA, and WRC-W702-B. All listed models run firmware that allows open-access management URLs, making them vulnerable before the official firmware release.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, while the EPSS is not available and the vulnerability is not in the CISA KEV catalog. The attack vector is likely local network access where an unauthenticated attacker on the same LAN can reach the vulnerable URLs. The lack of authentication enables complete control of the device, presenting a high risk of network compromise.
OpenCVE Enrichment