Junglewise Threat Intelligence

CVE-2026-59764: ELECOM Wireless Routers OS command injection in WebUI

CVE-2026-59764 · Severity: high · CVSS 7.2 · Published 2026-07-28

Vendors: Elecom.

Executive brief

ELECOM wireless routers and access points contain a security flaw in their web management interface. An attacker who has gained administrative login credentials can exploit this to take full control of the device by executing unauthorized system commands. This could lead to a complete compromise of the network traffic passing through the device or a total service outage.

Technical details

An OS command injection vulnerability (CWE-78) exists in the WebUI of specific ELECOM wireless LAN routers and access points. The flaw is located within the web management interface, specifically affecting the 'Restore Settings' functionality in related models. An attacker with high-level privileges (administrative access) can send specially crafted requests to the device to execute arbitrary OS commands. This allows for full system compromise, including data interception or persistent access. Users are advised to update to the latest firmware versions provided by the vendor to mitigate this risk.

Affected products

  • ELECOM WRC-X3000GS3-B v1.06 and earlier
  • ELECOM WRC-X3000GS3A-B v1.06 and earlier

Timeline

  • 2026-07-28: advisory: JPCERT/CC and ELECOM published advisories.
  • 2026-07-28: disclosed

References