ELECOM Wireless LAN Access Points OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in several models of ELECOM wireless LAN access points and routers. This vulnerability arises from improper handling of the username parameter, allowing authenticated users to execute arbitrary OS commands. The issue is present in multiple device models and versions, with no authentication required for exploitation.

Impact

Exploitation of this vulnerability allows for arbitrary OS command execution on the affected device, without the need for authentication.

Remediation

Users are advised to update the firmware to the latest version available for their specific device model.

Added: May 13, 2026, 4:13 PM
Updated: May 13, 2026, 4:13 PM

Vulnerability Rating

Custom Algorithm
spread
2.6
impact
7.5
exploitability
7.0
remediation
0.0
relevance
7.8
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.