2026-07-28 8:40CVE-2026-59764jpcert
PUBLISHED5.2CWE-78

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Problem type

Affected products

ELECOM CO.,LTD.

WRC-X3000GS3-B

<= v1.06 - AFFECTED

WRC-X3000GS3A-B

<= v1.06 - AFFECTED

References

GitHub Security Advisories

GHSA-5rfp-gm74-mxcc

ELECOM wireless LAN routers and access points devices contain an OS Command Injection...

https://github.com/advisories/GHSA-5rfp-gm74-mxcc

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-59764
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-59764",
    "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
    "assignerShortName": "jpcert",
    "dateUpdated": "2026-07-28T08:40:33.557Z",
    "dateReserved": "2026-07-13T01:43:55.938Z",
    "datePublished": "2026-07-28T08:40:33.557Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "shortName": "jpcert",
        "dateUpdated": "2026-07-28T08:40:33.557Z"
      },
      "descriptions": [
        {
          "lang": "en",
          "value": "ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product."
        }
      ],
      "affected": [
        {
          "vendor": "ELECOM CO.,LTD.",
          "product": "WRC-X3000GS3-B",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "v1.06"
            }
          ]
        },
        {
          "vendor": "ELECOM CO.,LTD.",
          "product": "WRC-X3000GS3A-B",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "v1.06"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en-US",
              "description": "Improper neutralization of special elements used in an OS command ('OS Command Injection')",
              "cweId": "CWE-78",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.elecom.co.jp/news/security/20260728-01/"
        },
        {
          "url": "https://jvn.jp/en/jp/JVN56870912/"
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en-US",
              "value": "GENERAL"
            }
          ],
          "cvssV3_0": {
            "version": "3.0",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "baseScore": 7.2,
            "baseSeverity": "HIGH"
          }
        },
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en-US",
              "value": "GENERAL"
            }
          ]
        }
      ]
    }
  }
}