JVN#56870912
Multiple vulnerabilities in ELECOM wireless LAN routers and access points (July 2026)
Overview
Multiple wireless LAN routers and access points provided by ELECOM CO.,LTD. contain multiple vulnerabilities.
Products Affected
CVE-2026-44387, CVE-2026-61376
- WAB-M1775-PS v2.1.9 and earlier
- WAB-S1775 v2.1.9 and earlier
- WAB-M2133 v2.0.5 and earlier
- WAB-I1750-PS v2.0.5 and earlier
- WAB-S1167-PS v2.0.5 and earlier
- WRC-X3000GS3-B v1.06 and earlier
- WRC-X3000GS3A-B v1.06 and earlier
Description
Multiple wireless LAN routers and access points provided by ELECOM CO.,LTD. contain multiple vulnerabilities listed below.
- Reflected cross-site scripting in WebUI (CWE-79)
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N Base Score 5.1
- CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score 5.2
- CVE-2026-44387
- OS command injection in WebUI (CWE-78)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.6
- CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Base Score 7.2
- CVE-2026-59764
- OS command injection in Restore Settings (CWE-78)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.6
- CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Base Score 7.2
- CVE-2026-61376
Impact
- An arbitrary script may be executed on a logged-in user's web browser (CVE-2026-44387).
- An arbitrary OS command may be executed by an attacker who can log in to the product (CVE-2026-59764, CVE-2026-61376).
Solution
Update the firmware
Update the firmware to the latest version according to the information provided by the developer.
Vendor Status
| Vendor | Status | Last Update | Vendor Notes |
|---|---|---|---|
| ELECOM CO.,LTD. | Vulnerable | 2026/07/28 | ELECOM CO.,LTD. website |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
CVE-2026-44387
Kentaro Ishii of GMO Cybersecurity by Ierae, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVE-2026-59764
Hirofumi Tanabe of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVE-2026-61376
Rintaro Kawasugi reported this vulnerability to ELECOM CO.,LTD. and coordinated. After the coordination was completed, ELECOM CO.,LTD. reported the case to JPCERT/CC to notify users of the solution through JVN.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-44387 |
|
CVE-2026-59764 |
|
|
CVE-2026-61376 |
|
| JVN iPedia |
JVNDB-2026-000103 |