ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
PUBLISHED5.2CWE-78
Problem type
Affected products
ELECOM CO.,LTD.
WAB-M1775-PS
<= v2.1.9 - AFFECTED
WAB-S1775
<= v2.1.9 - AFFECTED
WAB-M2133
<= v2.0.5 - AFFECTED
WAB-I1750-PS
<= v2.0.5 - AFFECTED
WAB-S1167-PS
<= v2.0.5 - AFFECTED
References
elecom.co.jp
https://www.elecom.co.jp/news/security/20260728-01/
jvn.jp
https://jvn.jp/en/jp/JVN56870912/
GitHub Security Advisories
GHSA-xp32-8g58-6x75
ELECOM wireless LAN routers and access points devices contain an OS Command Injection...
https://github.com/advisories/GHSA-xp32-8g58-6x75ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-61376Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-61376",
"assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"assignerShortName": "jpcert",
"dateUpdated": "2026-07-28T08:40:42.075Z",
"dateReserved": "2026-07-13T01:43:55.012Z",
"datePublished": "2026-07-28T08:40:42.075Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
"shortName": "jpcert",
"dateUpdated": "2026-07-28T08:40:42.075Z"
},
"descriptions": [
{
"lang": "en",
"value": "ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product."
}
],
"affected": [
{
"vendor": "ELECOM CO.,LTD.",
"product": "WAB-M1775-PS",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "v2.1.9"
}
]
},
{
"vendor": "ELECOM CO.,LTD.",
"product": "WAB-S1775",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "v2.1.9"
}
]
},
{
"vendor": "ELECOM CO.,LTD.",
"product": "WAB-M2133",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "v2.0.5"
}
]
},
{
"vendor": "ELECOM CO.,LTD.",
"product": "WAB-I1750-PS",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "v2.0.5"
}
]
},
{
"vendor": "ELECOM CO.,LTD.",
"product": "WAB-S1167-PS",
"defaultStatus": "unaffected",
"versions": [
{
"version": "0",
"status": "affected",
"versionType": "semver",
"lessThanOrEqual": "v2.0.5"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en-US",
"description": "Improper neutralization of special elements used in an OS command ('OS Command Injection')",
"cweId": "CWE-78",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://www.elecom.co.jp/news/security/20260728-01/"
},
{
"url": "https://jvn.jp/en/jp/JVN56870912/"
}
],
"metrics": [
{
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
],
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 7.2,
"baseSeverity": "HIGH"
}
},
{
"format": "CVSS",
"scenarios": [
{
"lang": "en-US",
"value": "GENERAL"
}
]
}
]
}
}
}