Junglewise Threat Intelligence

CVE-2026-35506: ELECOM Wireless LAN Access Points OS command injection in ping_ip_addr

CVE-2026-35506 · Severity: high · CVSS 7.2 · Published 2026-05-13

Technologies: Elecom WRC-BE72XSD-BA, Elecom WRC-BE72XSD-B, Elecom WRC-W702-B, Elecom WRC-BE65QSD-B. Vendors: Elecom.

Executive brief

ELECOM wireless LAN routers and access points are used to provide network connectivity in homes and offices. A security vulnerability in these devices allows a logged-in administrator to execute unauthorized commands on the device's operating system. This could lead to a complete takeover of the router, allowing an attacker to monitor network traffic or disrupt internet services.

Technical details

An OS command injection vulnerability (CWE-78) exists in multiple ELECOM wireless LAN routers and access points. The flaw is located in the handling of the 'ping_ip_addr' parameter, where the device fails to properly neutralize special elements before passing them to a system shell. An attacker with administrative privileges (PR:H) can exploit this over the network by sending a specially crafted request to the device's management interface. Successful exploitation allows for arbitrary command execution with the privileges of the web service, potentially leading to full system compromise. Users are advised to update to the latest firmware versions provided by the manufacturer.

Affected products

  • ELECOM WRC-BE72XSD-B v1.1.1 and earlier
  • ELECOM WRC-BE72XSD-BA v1.1.1 and earlier
  • ELECOM WRC-BE65QSD-B v1.1.0 and earlier
  • ELECOM WRC-W702-B v1.1.0 and earlier

Timeline

  • 2026-05-12: advisory: Initial advisory published by JVN/JPCERT
  • 2026-05-13: disclosed: CVE published to NVD

References

Related threats