ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
PUBLISHED5.2CWE-78
Problem type
Affected products
ELECOM CO.,LTD.
WRC-X3000GS3-B
<= v1.06 - AFFECTED
WRC-X3000GS3A-B
<= v1.06 - AFFECTED
References
elecom.co.jp
https://www.elecom.co.jp/news/security/20260728-01/
jvn.jp
https://jvn.jp/en/jp/JVN56870912/
GitHub Security Advisories
GHSA-5rfp-gm74-mxcc
ELECOM wireless LAN routers and access points devices contain an OS Command Injection...
https://github.com/advisories/GHSA-5rfp-gm74-mxccELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-59764Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-59764",
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"dateUpdated": "2026-07-28T08:40:33.557Z",
"dateReserved": "2026-07-13T01:43:55.938Z",
"datePublished": "2026-07-28T08:40:33.557Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert",
"dateUpdated": "2026-07-28T08:40:33.557Z"
},
"descriptions": [
{
"lang": "en",
"value": "ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product."
}
],
"affected": [
{
"vendor": "ELECOM CO.,LTD.",
"product": "WRC-X3000GS3-B",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "v1.06"
}
]
},
{
"vendor": "ELECOM CO.,LTD.",
"product": "WRC-X3000GS3A-B",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "v1.06"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en-US",
"description": "Improper neutralization of special elements used in an OS command ('OS Command Injection')",
"cweId": "CWE-78",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.elecom.co.jp/news/security/20260728-01/"
},
{
"url": "https://jvn.jp/en/jp/JVN56870912/"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
],
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 7.2,
"baseSeverity": "HIGH"
}
},
{
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
]
}
}
}