Junglewise Threat Intelligence

CVE-2026-40621: ELECOM Wireless LAN devices authentication bypass in web interface

CVE-2026-40621 · Severity: critical · CVSS 9.8 · Published 2026-05-13

Technologies: Elecom WRC-BE72XSD-BA, Elecom WRC-BE72XSD-B, Elecom WRC-W702-B, Elecom WRC-BE65QSD-B. Vendors: Elecom.

Executive brief

ELECOM wireless routers and access points are affected by a security flaw that allows unauthorized individuals to access administrative functions without a password. By visiting specific web addresses on the device, an attacker can take full control of the hardware, potentially monitoring network traffic or changing security settings. This could lead to a complete compromise of the local network's privacy and security.

Technical details

A vulnerability classified as CWE-288 (Authentication Bypass Using an Alternate Path or Channel) exists in several ELECOM wireless LAN products. The web management interface fails to enforce authentication checks on specific URLs, allowing a remote attacker to bypass the login screen and access administrative functions. This flaw can be exploited over the network without any user interaction or prior credentials. Successful exploitation allows the attacker to modify device configurations, potentially leading to full device takeover. Users are advised to update to the latest firmware versions provided by the manufacturer.

Affected products

  • ELECOM WRC-BE72XSD-B v1.1.1 and earlier
  • ELECOM WRC-BE72XSD-BA v1.1.1 and earlier
  • ELECOM WRC-BE65QSD-B v1.1.0 and earlier
  • ELECOM WRC-W702-B v1.1.0 and earlier

Timeline

  • 2026-05-12: advisory: Initial advisory published by JVN/JPCERT and ELECOM
  • 2026-05-13: disclosed: CVE published to NVD

References

Related threats