Junglewise Threat Intelligence

CVE-2026-42948: ELECOM Wireless LAN Access Point stored XSS in hostname parameter

CVE-2026-42948 · Severity: medium · CVSS 4.8 · Published 2026-05-13

Technologies: Elecom WAB-BE36-S, Elecom WAB-BE72-M, Elecom WAB-BE187-M, Elecom WAB-BE36-M. Vendors: Elecom.

Executive brief

ELECOM wireless LAN access points are affected by a security vulnerability that allows an administrator to inject malicious scripts into the management interface. If a second administrator views the affected settings page, the script could execute in their browser, potentially leading to unauthorized configuration changes or session hijacking. This risk is primarily relevant in environments where multiple administrative users manage the same networking hardware.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the web management interface of several ELECOM wireless LAN access points. The flaw stems from inadequate sanitization of the 'hostname' parameter. An attacker with administrative privileges can inject malicious JavaScript into this field, which is then stored on the device. When another administrator accesses the management page where this data is displayed, the script executes within the context of their session. This can lead to unauthorized actions being performed on behalf of the victim administrator. Users are advised to update to the latest firmware versions provided by the vendor.

Affected products

  • ELECOM WAB-BE187-M v1.1.10 and earlier
  • ELECOM WAB-BE72-M v1.1.3 and earlier
  • ELECOM WAB-BE36-M v1.1.3 and earlier
  • ELECOM WAB-BE36-S v1.1.3 and earlier

Timeline

  • 2026-05-12: advisory: Initial advisory published by JVN/JPCERT
  • 2026-05-13: disclosed: CVE record published

References

Related threats