CVE-2026-24449 Details
Description
For WRC-X1500GS-B and WRC-X1500GSA-B, the initial passwords can be calculated easily from the system information.
A vulnerability exists in ELECOM wireless LAN routers WRC-X1500GS-B and WRC-X1500GSA-B, all firmware versions, allowing initial passwords to be easily calculated from the system information. This weakness could lead to unauthorized access, as the default passwords can be exploited by malicious actors.
Users are advised to update the firmware to the latest version and change the default passwords for the admin interface and Wi-Fi connection to strong, unique ones. Instructions for updating the firmware and changing passwords are available on the ELECOM website.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Feb 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN94012927/ | [email protected] | Third Party Advisory |
| https://www.elecom.co.jp/news/security/20260203-01/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1391 | Use of Weak Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| elecom wrc-x1500gsa-b firmware | All versions |
CPE
Remediation
| |
| elecom wrc-x1500gsa-b | All versions |
CPE
Remediation
| |
| elecom wrc-x1500gs-b firmware | All versions |
CPE
Remediation
| |
| elecom wrc-x1500gs-b | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | Initial Analysis | [email protected] |
| Feb 3, 2026 | New CVE Received | [email protected] |