Executive brief
ELECOM wireless LAN routers and access points contain a security flaw in their web management interface. If a logged-in administrator visits a malicious link, an attacker could execute unauthorized scripts in their browser. This could allow an attacker to hijack the administrator's session or modify device settings.
Technical details
A reflected cross-site scripting (XSS) vulnerability exists in the WebUI of multiple ELECOM wireless LAN routers and access points (CWE-79). The vulnerability is triggered when the web interface fails to properly neutralize user-supplied input before including it in generated web pages. An attacker on the adjacent network can exploit this by tricking a logged-in user into clicking a specially crafted link. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's session, potentially leading to session hijacking or unauthorized configuration changes. Firmware updates have been released to address this issue.
Affected products
- ELECOM WAB-M1775-PS v2.1.9 and earlier
- ELECOM WAB-S1775 v2.1.9 and earlier
- ELECOM WAB-M2133 v2.0.5 and earlier
- ELECOM WAB-I1750-PS v2.0.5 and earlier
- ELECOM WAB-S1167-PS v2.0.5 and earlier
Timeline
- 2026-07-28: advisory
- 2026-07-28: patched