CVE-2026-59764
Received Received - Intake

OS Command Injection in ELECOM Wireless LAN Routers

Vulnerability report for CVE-2026-59764, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-28

Last updated on: 2026-07-28

Assigner: JPCERT/CC

Description

ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-28
Last Modified
2026-07-28
Generated
2026-07-28
AI Q&A
2026-07-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
elecom wlan_router *
elecom access_point *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an OS Command Injection flaw in ELECOM wireless LAN routers and access points. It allows an attacker who can log in to the device to execute arbitrary operating system commands through the WebUI interface.

Detection Guidance

This vulnerability can be detected by checking for unauthorized command execution attempts in logs or by inspecting network traffic for suspicious activity targeting ELECOM wireless LAN routers or access points. No specific commands are provided in the context.

Impact Analysis

An attacker could gain control over the affected device, potentially leading to network compromise, data theft, or disruption of network services. This could affect both home and enterprise users relying on these devices.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating privacy regulations like GDPR or HIPAA. Organizations using these devices may face compliance violations and legal consequences.

Mitigation Strategies

Immediate steps include restricting access to the WebUI of affected devices, applying firmware updates if available, and monitoring for unusual activity. Since the vulnerability allows arbitrary OS command execution, limiting access to trusted users is critical.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59764. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart