CVE-2025-41427HIGH 8.8EPSS p58.1%

CVE-2025-41427CVE-2025-41427

Description

WRC-X3000GS, WRC-X3000GSA, and WRC-X3000GSN contain an improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability in Connection Diagnostics page. If a remote authenticated attacker sends a specially crafted request to the affected product, an arbitrary OS command may be executed.

Scoring

CVSS 3.08.8 (HIGH)
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS1.00% probability of exploitation · percentile 58.1% · 2026-06-18T12:00:27Z
Published2025-06-24
Last modified2026-04-15

Underlying weaknesses· 1

CWE-78

References

  1. https://jvn.jp/en/jp/JVN39435597/
  2. https://www.elecom.co.jp/news/security/20250624-01/

1

TypeTargetConfidenceTier
WeaknessImproper Neutralization of Special Elements used in an OS Command ('OS Command Injection')cwe-780%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-43879
CVE
CVE-2025-48890
CVE
CVE-2025-3626
CVE
CVE-2025-46272
CVE
CVE-2025-37162
CVE
CVE-2025-6541
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.