Security · 1h ago
ELECOM Router Flaws Allow OS Command Injection via Admin Panel
ELECOM disclosed three vulnerabilities in its wireless routers and access points, including OS command injection flaws (CVE-2026-59764, CVE-2026-61376) and a reflected XSS bug (CVE-2026-44387). An attacker with admin credentials can execute arbitrary commands on the device, potentially modifying DNS or forwarding settings. The XSS vulnerability could be used to trick an admin into performing unintended actions.
Meridian48 take
The vulnerabilities require admin access or user interaction, limiting immediate risk, but they highlight the persistent danger of command injection in embedded devices.
Read the full reporting
ELECOM Wireless LAN Devices JVN#56870912: OS Command Injection in Management Screen and Configuration Restoration →
DEV Community
elecomcommand-injection