Junglewise Threat Intelligence

CVE-2026-61376: ELECOM Wireless LAN Routers OS command injection in Restore Settings

CVE-2026-61376 · Severity: high · CVSS 7.2 · Published 2026-07-28

Vendors: Elecom.

Executive brief

ELECOM wireless routers and access points, which provide network connectivity for offices and homes, contain a security flaw in their settings restoration feature. An attacker who has gained administrative access to the device's management interface can use this flaw to take full control of the hardware. This could lead to a complete disruption of internet services or unauthorized access to network traffic.

Technical details

An OS command injection vulnerability (CWE-78) exists in the 'Restore Settings' functionality of several ELECOM wireless LAN routers and access points. The flaw stems from improper neutralization of special elements within the settings restoration process, allowing an attacker to inject and execute arbitrary OS commands. Exploitation requires the attacker to be authenticated with high privileges (administrative access) to the device's web-based management interface. Successful exploitation grants the attacker full control over the underlying operating system. Users are advised to update their firmware to the latest available versions provided by the vendor.

Affected products

  • ELECOM WAB-M1775-PS v2.1.9 and earlier
  • ELECOM WAB-S1775 v2.1.9 and earlier
  • ELECOM WAB-M2133 v2.0.5 and earlier
  • ELECOM WAB-I1750-PS v2.0.5 and earlier
  • ELECOM WAB-S1167-PS v2.0.5 and earlier

Timeline

  • 2026-07-28: advisory: JPCERT/CC and ELECOM published the advisory.
  • 2026-07-28: disclosed

References

Related threats