CVE-2026-61376
ELECOM · WAB-M1775-PS, WAB-S1775, WAB-M2133, WAB-I1750-PS, WAB-S1167-PS
Multiple ELECOM wireless LAN access points contain an OS command injection vulnerability in the Restore Settings function, allowing administrative users to execute arbitrary system commands.
Executive summary
A critical OS command injection flaw in the restore functionality of ELECOM wireless LAN access points could allow authenticated attackers to gain full control of the device.
Vulnerability
This is an OS command injection vulnerability (CWE-78) triggered through the Restore Settings interface. The vulnerability requires the attacker to possess high privileges (PR:H), effectively limiting the threat to those who have already bypassed or obtained legitimate administrative authentication.
Business impact
With a CVSS score of 8.6, this vulnerability poses a severe risk to network infrastructure. If exploited, an attacker could gain persistent control over the network hardware, facilitate traffic interception, or disable security controls, leading to broad data compromise across the connected environment.
Remediation
Immediate Action: Identify all deployed ELECOM access points and prepare for a mandatory firmware update cycle as soon as the vendor issues the official patches.
Proactive Monitoring: Monitor management traffic for unauthorized requests to the configuration restoration endpoints and maintain strict audit logs for administrative actions.
Compensating Controls: Limit access to the administrative management interface to dedicated, secure jump hosts to ensure that only authorized personnel can interact with sensitive configuration functions.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations should treat this high-severity vulnerability with urgency. Given the potential for full administrative takeover of networking hardware, apply patches as soon as they become available from the manufacturer.