Executive brief
ELECOM wireless routers and access points contain a critical security flaw that allows an attacker to take full control of the device. By sending a specially crafted request to the device's management interface, an unauthorized person can execute system-level commands without needing a password. This could lead to the interception of network traffic, unauthorized access to the local network, or a complete shutdown of internet services.
Technical details
An OS command injection vulnerability (CWE-78) exists in several ELECOM wireless LAN routers and access points due to improper neutralization of special elements within the 'username' parameter. The flaw is reachable over the network and does not require any authentication or user interaction. An attacker can exploit this by sending a crafted HTTP request to the device, leading to arbitrary command execution with the privileges of the web service (typically root on embedded devices). Affected models include WRC-BE72XSD-B, WRC-BE72XSD-BA, WRC-BE65QSD-B, and WRC-W702-B. Users are advised to update to the latest firmware versions provided by the vendor.
Affected products
- ELECOM WRC-BE72XSD-B v1.1.1 and earlier
- ELECOM WRC-BE72XSD-BA v1.1.1 and earlier
- ELECOM WRC-BE65QSD-B v1.1.0 and earlier
- ELECOM WRC-W702-B v1.1.0 and earlier
Timeline
- 2026-05-12: advisory: Initial advisory published by JVN and ELECOM
- 2026-05-13: disclosed: CVE published to NVD