Executive brief
ELECOM wireless routers and access points contain a security flaw in their web management interface. An attacker who has gained administrative login credentials can exploit this to take full control of the device by executing unauthorized system commands. This could lead to a complete compromise of the network traffic passing through the device or a total service outage.
Technical details
An OS command injection vulnerability (CWE-78) exists in the WebUI of specific ELECOM wireless LAN routers and access points. The flaw is located within the web management interface, specifically affecting the 'Restore Settings' functionality in related models. An attacker with high-level privileges (administrative access) can send specially crafted requests to the device to execute arbitrary OS commands. This allows for full system compromise, including data interception or persistent access. Users are advised to update to the latest firmware versions provided by the vendor to mitigate this risk.
Affected products
- ELECOM WRC-X3000GS3-B v1.06 and earlier
- ELECOM WRC-X3000GS3A-B v1.06 and earlier
Timeline
- 2026-07-28: advisory: JPCERT/CC and ELECOM published advisories.
- 2026-07-28: disclosed