Executive brief
ELECOM wireless LAN access points are affected by a security vulnerability that allows an administrator to inject malicious scripts into the management interface. If a second administrator views the affected settings page, the script could execute in their browser, potentially leading to unauthorized configuration changes or session hijacking. This risk is primarily relevant in environments where multiple administrative users manage the same networking hardware.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the web management interface of several ELECOM wireless LAN access points. The flaw stems from inadequate sanitization of the 'hostname' parameter. An attacker with administrative privileges can inject malicious JavaScript into this field, which is then stored on the device. When another administrator accesses the management page where this data is displayed, the script executes within the context of their session. This can lead to unauthorized actions being performed on behalf of the victim administrator. Users are advised to update to the latest firmware versions provided by the vendor.
Affected products
- ELECOM WAB-BE187-M v1.1.10 and earlier
- ELECOM WAB-BE72-M v1.1.3 and earlier
- ELECOM WAB-BE36-M v1.1.3 and earlier
- ELECOM WAB-BE36-S v1.1.3 and earlier
Timeline
- 2026-05-12: advisory: Initial advisory published by JVN/JPCERT
- 2026-05-13: disclosed: CVE record published