Executive brief
ELECOM wireless routers and access points are affected by a security flaw that allows unauthorized individuals to access administrative functions without a password. By visiting specific web addresses on the device, an attacker can take full control of the hardware, potentially monitoring network traffic or changing security settings. This could lead to a complete compromise of the local network's privacy and security.
Technical details
A vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) exists in several ELECOM wireless LAN products. The web management interface fails to enforce authentication checks on specific URLs, allowing a remote attacker to bypass the login screen and access administrative functions. This flaw can be exploited over the network without any user interaction or prior credentials. Successful exploitation allows the attacker to modify device configurations, potentially leading to full device takeover. Users are advised to update to the latest firmware versions provided by the manufacturer.
Affected products
- ELECOM WRC-BE72XSD-B v1.1.1 and earlier
- ELECOM WRC-BE72XSD-BA v1.1.1 and earlier
- ELECOM WRC-BE65QSD-B v1.1.0 and earlier
- ELECOM WRC-W702-B v1.1.0 and earlier
Timeline
- 2026-05-12: advisory: Initial advisory published by JVN/JPCERT and ELECOM
- 2026-05-13: disclosed: CVE published to NVD