No Password Required: 9.8 Severity ELECOM Router Flaws Allow Total Network Takeover
ID: c7001f97-1553-5e7e-bf07-01fed12b4c5d
STIX ID: report--c7001f97-1553-5e7e-bf07-01fed12b4c5d
Feed Name: securityonline.info
JPCERT/CC has published an urgent advisory detailing multiple critical vulnerabilities in ELECOM routers and access points—most notably unauthenticated OS command injection (CVE-2026-42062) and authentication bypass/missing-authentication (CVE-2026-40621) with CVSS scores up to 9.8—affecting several WRC-X, WRC-BE, and WAB-BE series models; the advisory urges immediate firmware updates and disabling unnecessary remote management while also noting additional issues such as hard-coded keys, stored XSS, and CSRF weaknesses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
