ELECOM Routers Hit by OS Command Injection and XSS Flaws, Patches Urged
Japan's JVN disclosed three vulnerabilities on July 28, 2026, affecting multiple ELECOM wireless LAN routers and access points, including the WAB and WRC-X3000GS3 series. Two flaws — CVE-2026-59764 and CVE-2026-61376 — allow an authenticated administrator to execute arbitrary OS commands via the management screen or configuration restoration function. A third vulnerability, CVE-2026-44387, enables reflected cross-site scripting that could be used to hijack management sessions when a user on an adjacent network opens a crafted URL. Potential consequences include DNS tampering, traffic redirection, credential theft, and use of the device as an internal network pivot point. ELECOM and JVN recommend applying the latest firmware and restricting management screen access through VLANs or access control lists.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in