Junglewise Threat Intelligence

CVE-2026-42062: ELECOM Wireless LAN Devices OS command injection in username parameter

CVE-2026-42062 · Severity: critical · CVSS 9.8 · Published 2026-05-13

Technologies: Elecom WRC-BE72XSD-BA, Elecom WRC-BE72XSD-B, Elecom WRC-W702-B, Elecom WRC-BE65QSD-B. Vendors: Elecom.

Executive brief

ELECOM wireless routers and access points contain a critical security flaw that allows an attacker to take full control of the device. By sending a specially crafted request to the device's management interface, an unauthorized person can execute system-level commands without needing a password. This could lead to the interception of network traffic, unauthorized access to the local network, or a complete shutdown of internet services.

Technical details

An OS command injection vulnerability (CWE-78) exists in several ELECOM wireless LAN routers and access points due to improper neutralization of special elements within the 'username' parameter. The flaw is reachable over the network and does not require any authentication or user interaction. An attacker can exploit this by sending a crafted HTTP request to the device, leading to arbitrary command execution with the privileges of the web service (typically root on embedded devices). Affected models include WRC-BE72XSD-B, WRC-BE72XSD-BA, WRC-BE65QSD-B, and WRC-W702-B. Users are advised to update to the latest firmware versions provided by the vendor.

Affected products

  • ELECOM WRC-BE72XSD-B v1.1.1 and earlier
  • ELECOM WRC-BE72XSD-BA v1.1.1 and earlier
  • ELECOM WRC-BE65QSD-B v1.1.0 and earlier
  • ELECOM WRC-W702-B v1.1.0 and earlier

Timeline

  • 2026-05-12: advisory: Initial advisory published by JVN and ELECOM
  • 2026-05-13: disclosed: CVE published to NVD

References

Related threats