2026-07-28 8:40CVE-2026-61376jpcert
PUBLISHED5.2CWE-78

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

Problem type

Affected products

ELECOM CO.,LTD.

WAB-M1775-PS

<= v2.1.9 - AFFECTED

WAB-S1775

<= v2.1.9 - AFFECTED

WAB-M2133

<= v2.0.5 - AFFECTED

WAB-I1750-PS

<= v2.0.5 - AFFECTED

WAB-S1167-PS

<= v2.0.5 - AFFECTED

References

GitHub Security Advisories

GHSA-xp32-8g58-6x75

ELECOM wireless LAN routers and access points devices contain an OS Command Injection...

https://github.com/advisories/GHSA-xp32-8g58-6x75

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-61376
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-61376",
    "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
    "assignerShortName": "jpcert",
    "dateUpdated": "2026-07-28T08:40:42.075Z",
    "dateReserved": "2026-07-13T01:43:55.012Z",
    "datePublished": "2026-07-28T08:40:42.075Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "shortName": "jpcert",
        "dateUpdated": "2026-07-28T08:40:42.075Z"
      },
      "descriptions": [
        {
          "lang": "en",
          "value": "ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product."
        }
      ],
      "affected": [
        {
          "vendor": "ELECOM CO.,LTD.",
          "product": "WAB-M1775-PS",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "v2.1.9"
            }
          ]
        },
        {
          "vendor": "ELECOM CO.,LTD.",
          "product": "WAB-S1775",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "v2.1.9"
            }
          ]
        },
        {
          "vendor": "ELECOM CO.,LTD.",
          "product": "WAB-M2133",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "v2.0.5"
            }
          ]
        },
        {
          "vendor": "ELECOM CO.,LTD.",
          "product": "WAB-I1750-PS",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "v2.0.5"
            }
          ]
        },
        {
          "vendor": "ELECOM CO.,LTD.",
          "product": "WAB-S1167-PS",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "0",
              "status": "affected",
              "versionType": "semver",
              "lessThanOrEqual": "v2.0.5"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en-US",
              "description": "Improper neutralization of special elements used in an OS command ('OS Command Injection')",
              "cweId": "CWE-78",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.elecom.co.jp/news/security/20260728-01/"
        },
        {
          "url": "https://jvn.jp/en/jp/JVN56870912/"
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en-US",
              "value": "GENERAL"
            }
          ],
          "cvssV3_0": {
            "version": "3.0",
            "vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
            "baseScore": 7.2,
            "baseSeverity": "HIGH"
          }
        },
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en-US",
              "value": "GENERAL"
            }
          ]
        }
      ]
    }
  }
}