Description
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Published: 2026-07-28
Score: 8.6 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An OS Command Injection flaw exists in the WebUI of certain ELECOM wireless LAN routers and access points. The vulnerability permits an attacker who has authenticated access to the device to inject arbitrary operating‑system commands, effectively granting remote code execution with the privileges of the router. The flaw stems from inadequate validation of user input before passing it to system commands, as identified by CWE‑78. An attacker could use this to compromise the device, intercept traffic, or pivot to additional network targets.

Affected Systems

Devices affected are the ELECOM WRC‑X3000GS3‑B and WRC‑X3000GS3A‑B series routers and access points. No specific firmware or MAC address ranges were disclosed, so any unit of these models currently deployed remains a potential target until confirmed patched.

Risk and Exploitability

The CVSS score of 8.6 classifies this flaw as high severity, and the EPSS score of 1% indicates a low‑to‑moderate likelihood of exploitation, though it is not yet listed in the CISA KEV catalog. Exploitation requires a valid login to the WebUI, so attackers must first breach credentials or obtain remote access to the administrative interface. Once authenticated, the attacker can execute any command, giving full control over the device. No publicly available exploits have been reported at this time, but the potential impact and high score warrant prompt action.

Generated by OpenCVE AI on August 3, 2026 at 15:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the recent firmware update released by ELECOM that fixes the command‑injection vulnerability.
  • If the update is not immediately available, restrict physical and logical access to the device by enabling firewall rules to block the WebUI from untrusted networks and limiting login to known internal IP addresses.
  • Disable the WebUI interface entirely if it is not required for operation, or enforce strong, unique credentials and two‑factor authentication where supported.

Generated by OpenCVE AI on August 3, 2026 at 15:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 03 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Title Remote Command Execution via OS Command Injection in ELECOM Wireless Router WebUI

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Elecom
Elecom wrc-x3000gs3-b
Elecom wrc-x3000gs3a-b
Vendors & Products Elecom
Elecom wrc-x3000gs3-b
Elecom wrc-x3000gs3a-b

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in WebUI. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Weaknesses CWE-78
References
Metrics cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Elecom Wrc-x3000gs3-b Wrc-x3000gs3a-b
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-07-28T16:08:58.531Z

Reserved: 2026-07-13T01:43:55.938Z

Link: CVE-2026-59764

cve-icon Vulnrichment

Updated: 2026-07-28T16:08:55.436Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T09:16:42.417

Modified: 2026-07-28T16:19:23.777

Link: CVE-2026-59764

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T15:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')