Impact
ELECOM wireless LAN routers and access points contain a reflected cross‑site scripting vulnerability in the WebUI. An attacker can inject an arbitrary script that will run in the browser of any user who is logged into the device, enabling malicious code execution on the client side.
Affected Systems
The affected products are ELECOM WAB‑I1750‑PS, WAB‑M1775‑PS, WAB‑M2133, WAB‑S1167‑PS, and WAB‑S1775. No specific firmware version range is documented.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk level, while the EPSS score of <1% suggests that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is the device’s WebUI, which requires the user to be authenticated; once logged in, a malicious actor can provide crafted input that triggers the vulnerable reflection and executes arbitrary scripts.
OpenCVE Enrichment