Description
ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Published: 2026-07-28
Score: 8.6 High
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Elecom devices such as the WAB-I1750-PS, WAB-M1775-PS, WAB-M2133, WAB-S1167-PS, and WAB-S1775 routers contain an OS command injection flaw in the Restore Settings function. An attacker who can authenticate to the device can inject arbitrary operating system commands, allowing execution with the privileges of the web server process. This vulnerability can lead to complete compromise of the affected device, enabling the attacker to modify configuration, exfiltrate data, or pivot to other network assets.

Affected Systems

The affected models are ELECOM wireless LAN routers and access points under the brand names WAB-I1750-PS, WAB-M1775-PS, WAB-M2133, WAB-S1167-PS, and WAB-S1775. No specific firmware ranges were listed, so all firmware versions of these models are potentially vulnerable unless a patch has been released.

Risk and Exploitability

The CVSS score of 8.6 points to high severity. The EPSS score of 1% indicates that the likelihood of exploitation is low to moderate, but the presence of an authenticated command injection makes it a serious threat. The vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker to have login credentials; therefore, the exploitation vector is an authenticated network attack, most likely via the device’s management web interface.

Generated by OpenCVE AI on August 4, 2026 at 13:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Elecom website for the latest firmware update for your specific router model and apply the patch immediately.
  • If a patch is not yet available, disable the Restore Settings feature via the device configuration or block access to the management interface from untrusted networks.
  • Ensure strong, unique passwords for all device accounts and consider using network segmentation to limit exposure of the wireless LAN controllers.

Generated by OpenCVE AI on August 4, 2026 at 13:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Restore Settings of ELECOM Wireless LAN Devices

Sun, 02 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
Title OS Command Injection in Restore Settings of ELECOM Wireless LAN Devices

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Elecom
Elecom wab-i1750-ps
Elecom wab-m1775-ps
Elecom wab-m2133
Elecom wab-s1167-ps
Elecom wab-s1775
Vendors & Products Elecom
Elecom wab-i1750-ps
Elecom wab-m1775-ps
Elecom wab-m2133
Elecom wab-s1167-ps
Elecom wab-s1775

Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description ELECOM wireless LAN routers and access points devices contain an OS Command Injection vulnerability in Restore Settings. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
Weaknesses CWE-78
References
Metrics cvssV3_0

{'score': 7.2, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Elecom Wab-i1750-ps Wab-m1775-ps Wab-m2133 Wab-s1167-ps Wab-s1775
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-07-28T16:08:35.015Z

Reserved: 2026-07-13T01:43:55.012Z

Link: CVE-2026-61376

cve-icon Vulnrichment

Updated: 2026-07-28T16:08:29.490Z

cve-icon NVD

Status : Deferred

Published: 2026-07-28T09:16:42.553

Modified: 2026-07-28T16:19:27.750

Link: CVE-2026-61376

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T13:15:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')