Published:2026/07/28  Last Updated:2026/07/28

JVN#56870912
Multiple vulnerabilities in ELECOM wireless LAN routers and access points (July 2026)

Overview

Multiple wireless LAN routers and access points provided by ELECOM CO.,LTD. contain multiple vulnerabilities.

Products Affected

CVE-2026-44387, CVE-2026-61376

  • WAB-M1775-PS v2.1.9 and earlier
  • WAB-S1775 v2.1.9 and earlier
  • WAB-M2133 v2.0.5 and earlier
  • WAB-I1750-PS v2.0.5 and earlier
  • WAB-S1167-PS v2.0.5 and earlier
CVE-2026-59764
  • WRC-X3000GS3-B v1.06 and earlier
  • WRC-X3000GS3A-B v1.06 and earlier

Description

Multiple wireless LAN routers and access points provided by ELECOM CO.,LTD. contain multiple vulnerabilities listed below.

  • Reflected cross-site scripting in WebUI (CWE-79)
    • CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N Base Score 5.1
    • CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Base Score 5.2
    • CVE-2026-44387
  • OS command injection in WebUI (CWE-78)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.6
    • CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Base Score 7.2
    • CVE-2026-59764
  • OS command injection in Restore Settings (CWE-78)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.6
    • CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Base Score 7.2
    • CVE-2026-61376

Impact

  • An arbitrary script may be executed on a logged-in user's web browser (CVE-2026-44387).
  • An arbitrary OS command may be executed by an attacker who can log in to the product (CVE-2026-59764, CVE-2026-61376).

Solution

Update the firmware
Update the firmware to the latest version according to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
ELECOM CO.,LTD. Vulnerable 2026/07/28 ELECOM CO.,LTD. website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

CVE-2026-44387
Kentaro Ishii of GMO Cybersecurity by Ierae, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2026-59764
Hirofumi Tanabe of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

CVE-2026-61376
Rintaro Kawasugi reported this vulnerability to ELECOM CO.,LTD. and coordinated. After the coordination was completed, ELECOM CO.,LTD. reported the case to JPCERT/CC to notify users of the solution through JVN.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-44387
CVE-2026-59764
CVE-2026-61376
JVN iPedia JVNDB-2026-000103