CVE-2026-59764
ELECOM · WRC-X3000GS3-B and WRC-X3000GS3A-B
ELECOM wireless LAN routers are affected by an OS command injection vulnerability in the WebUI, which allows authenticated administrative users to execute arbitrary commands.
Executive summary
An OS command injection vulnerability in ELECOM wireless LAN routers allows high-privilege attackers to execute arbitrary system commands, posing a risk of total system compromise.
Vulnerability
The vulnerability is an OS command injection flaw (CWE-78) located in the router WebUI. Exploitation requires administrative privileges (PR:H), meaning an attacker must already have authenticated access to the device management interface.
Business impact
Successful exploitation of this command injection vulnerability allows an attacker to execute arbitrary code on the underlying operating system of the router. Given the CVSS score of 8.6, this represents a high-severity risk that could lead to full device takeover, persistent unauthorized access to the network, and the potential for lateral movement into protected internal segments.
Remediation
Immediate Action: Administrators should verify their current firmware version and apply the latest security updates provided by ELECOM immediately upon availability.
Proactive Monitoring: Review device management access logs for unusual administrative activity or attempts to access restricted WebUI functions.
Compensating Controls: Restrict access to the router WebUI to trusted management IP addresses only, and ensure that administrative credentials are complex and rotated regularly to prevent unauthorized access.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
The severity of this vulnerability necessitates prompt attention to vendor security bulletins. While administrative access is required for exploitation, the risk of total system compromise is significant, and administrators should prioritize updating affected firmware as soon as patches are released.