Executive brief
ELECOM wireless LAN routers and access points are used to provide network connectivity in homes and offices. A security vulnerability in these devices allows a logged-in administrator to execute unauthorized commands on the device's operating system. This could lead to a complete takeover of the router, allowing an attacker to monitor network traffic or disrupt internet services.
Technical details
An OS command injection vulnerability (CWE-78) exists in multiple ELECOM wireless LAN routers and access points. The flaw is located in the handling of the 'ping_ip_addr' parameter, where the device fails to properly neutralize special elements before passing them to a system shell. An attacker with administrative privileges (PR:H) can exploit this over the network by sending a specially crafted request to the device's management interface. Successful exploitation allows for arbitrary command execution with the privileges of the web service, potentially leading to full system compromise. Users are advised to update to the latest firmware versions provided by the manufacturer.
Affected products
- ELECOM WRC-BE72XSD-B v1.1.1 and earlier
- ELECOM WRC-BE72XSD-BA v1.1.1 and earlier
- ELECOM WRC-BE65QSD-B v1.1.0 and earlier
- ELECOM WRC-W702-B v1.1.0 and earlier
Timeline
- 2026-05-12: advisory: Initial advisory published by JVN/JPCERT
- 2026-05-13: disclosed: CVE published to NVD