Executive brief
ELECOM wireless LAN access points are affected by a security flaw in how they verify administrative requests. If an authenticated administrator visits a malicious website, an attacker could trick their browser into performing unauthorized configuration changes on the device. This could lead to unauthorized modifications of network settings or other administrative actions without the user's consent.
Technical details
This vulnerability is a Cross-Site Request Forgery (CSRF) resulting from the use of an invariant value in a dynamically changing context (CWE-344). While the affected ELECOM wireless LAN access points implement a CSRF protection mechanism, the handling of CSRF tokens is inadequate, allowing for predictable or static values that do not sufficiently validate the origin of the request. An attacker can exploit this by hosting a malicious page that sends unauthorized requests to the device's management interface. If an administrator with an active session visits the malicious page, the device will process the attacker's requests as if they were legitimate, potentially leading to unauthorized configuration changes. Users are advised to update to the latest firmware versions provided by the vendor.
Affected products
- ELECOM WAB-BE187-M v1.1.10 and earlier
- ELECOM WAB-BE72-M v1.1.3 and earlier
- ELECOM WAB-BE36-M v1.1.3 and earlier
- ELECOM WAB-BE36-S v1.1.3 and earlier
Timeline
- 2026-05-12: advisory: Initial advisory published by JVN/JPCERT
- 2026-05-13: disclosed: CVE published to NVD