CVE-2025-53472
7.2ELECOM · WRC-BE36QS-B and WRC-W701-B
ELECOM routers WRC-BE36QS-B and WRC-W701-B contain an OS command injection vulnerability in the WebGUI, allowing an authenticated remote attacker to execute arbitrary commands.
Executive summary
An OS command injection vulnerability in ELECOM WRC-BE36QS-B and WRC-W701-B routers allows authenticated remote attackers to achieve full system compromise.
Vulnerability
This vulnerability, classified as CWE-78, exists due to improper neutralization of special elements within the WebGUI interface. An attacker with administrative access to the WebGUI can inject and execute arbitrary operating system commands with elevated privileges.
Business impact
The exploitation of this vulnerability allows for complete control over the affected network hardware. This poses a significant risk of unauthorized access to internal network traffic, potential interception of sensitive data, and the establishment of persistent backdoors within the network infrastructure. With a CVSS score of 7.2, this high-severity flaw requires immediate attention to prevent lateral movement and potential compromise of connected enterprise systems.
Remediation
Immediate Action: Review the official ELECOM security advisory at https://www.elecom.co.jp/news/security/20250722-01/ for firmware update availability and apply patches to all affected units.
Proactive Monitoring: Monitor device administrative logs for unusual login activity or suspicious command execution patterns originating from the WebGUI management interface.
Compensating Controls: Restrict access to the WebGUI interface to trusted management IP addresses only and disable remote management features if they are not strictly required for business operations.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for total system compromise, organizations currently utilizing the affected ELECOM hardware must prioritize the identification and patching of all instances. If a vendor patch is not yet available, administrators should immediately isolate these devices from external network access to mitigate the risk of remote exploitation by unauthorized actors.