logo

No Password Required: 9.8 Severity ELECOM Router Flaws Allow Total Network Takeover

ID: c7001f97-1553-5e7e-bf07-01fed12b4c5d

STIX ID: report--c7001f97-1553-5e7e-bf07-01fed12b4c5d

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-15

Date Updated: 2026-05-15

Author: Ddos

...
...

JPCERT/CC has published an urgent advisory detailing multiple critical vulnerabilities in ELECOM routers and access points—most notably unauthenticated OS command injection (CVE-2026-42062) and authentication bypass/missing-authentication (CVE-2026-40621) with CVSS scores up to 9.8—affecting several WRC-X, WRC-BE, and WAB-BE series models; the advisory urges immediate firmware updates and disabling unnecessary remote management while also noting additional issues such as hard-coded keys, stored XSS, and CSRF weaknesses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.