Executive brief
ELECOM wireless LAN access points are affected by a vulnerability that fails to properly validate language settings. If an administrator visits a malicious website while logged into the device's management interface, the attacker can cause the administration page to malfunction or become unusable. This can disrupt the ability of staff to manage the network hardware.
Technical details
A vulnerability classified as Improper Check for Unusual or Exceptional Conditions (CWE-754) exists in the web management interface of several ELECOM wireless access points. The application fails to validate the 'language' parameter, allowing it to be set to unexpected or inappropriate values. An attacker can exploit this via a Cross-Site Request Forgery (CSRF) style attack by tricking a logged-in administrator into visiting a malicious URL. Successful exploitation results in a partial denial of service where the administrative web interface becomes 'broken' or inaccessible to the user. Firmware updates are available to resolve this issue.
Affected products
- ELECOM WAB-BE187-M v1.1.10 and earlier
- ELECOM WAB-BE72-M v1.1.3 and earlier
- ELECOM WAB-BE36-M v1.1.3 and earlier
- ELECOM WAB-BE36-S v1.1.3 and earlier
Timeline
- 2026-05-12: advisory: Initial disclosure by JVN/JPCERT
- 2026-05-13: disclosed: NVD publication date