Three flaws across seven ELECOM Wi-Fi routers and access points (CVE-2026-59764)
Three flaws in seven ELECOM Wi-Fi routers and access points, July 28 2026. Fixed firmware shipped in May and June; the consumer models auto-update by default.
Table of contents
Three flaws in seven ELECOM Wi-Fi routers and access points, July 28 2026. Fixed firmware shipped in May and June; the consumer models auto-update by default.
On July 28, 2026, Japan's JVN disclosed three vulnerabilities across seven ELECOM wireless LAN routers and business access points. Two of them let an attacker who can log in to the settings screen run arbitrary commands on the device itself. Take over a router and you can read the traffic passing through it, or use it as a launch pad against someone else.
The reassuring part first. Fixed firmware has been available since May and June — well before the disclosure. And on the two consumer routers, updates install themselves unless someone changed the default. Nothing here calls for pulling equipment offline in a hurry.
Who does need to act: households that turned auto-update off, and organisations running the five business access points, which are updated by hand. Below is a model-by-model table of the firmware to move to, followed by a harder question — whether "the attacker needs to log in" is really the reassurance it sounds like — answered with ELECOM's own history.
The seven affected models and the firmware to move to
Match your model number and the firmware version shown in its settings screen against this table. If you fall in the "affected" column, move to the version on its right. Release dates for the fixes are included — if your device updated after that date, you are already covered.
| Model | Type | CVE(s) | Affected | Safe version | Fix released |
|---|---|---|---|---|---|
| WRC-X3000GS3-B | Consumer router | CVE-2026-59764 | v1.06 and below | Ver.1.07 or later | 2026/06/15 |
| WRC-X3000GS3A-B | Consumer router | CVE-2026-59764 | v1.06 and below | Ver.1.07 or later | 2026/06/15 |
| WAB-M1775-PS | Business AP | CVE-2026-61376 CVE-2026-44387 | v2.1.9 and below | Ver.2.1.12 or later | 2026/06/08 |
| WAB-S1775 | Business AP | CVE-2026-61376 CVE-2026-44387 | v2.1.9 and below | Ver.2.1.12 or later | 2026/05/25 |
| WAB-M2133 | Business AP | CVE-2026-61376 CVE-2026-44387 | v2.0.5 and below | Ver.2.0.13 or later | 2026/06/08 |
| WAB-I1750-PS | Business AP | CVE-2026-61376 CVE-2026-44387 | v2.0.5 and below | Ver.2.0.7 or later | 2026/06/08 |
| WAB-S1167-PS | Business AP | CVE-2026-61376 CVE-2026-44387 | v2.0.5 and below | Ver.2.0.7 or later | 2026/06/08 |
One oddity worth catching: WAB-M2133 is listed as affected at "v2.0.5 and below" but its fix is Ver.2.0.13, while the other two models sharing that same affected string are fixed at Ver.2.0.7. Identical affected ranges, different fix branches — so check the download page for your exact model number. No device in this round has been declared end-of-support; all seven have fixes.
ELECOM's notice is advisory EL42-098, and the remedy it gives is firmware update only — no workarounds are offered. JVN#56870912 carries the same content, but JVN does not print specific version numbers, so the numbers above come from ELECOM's advisory and each model's download page.
What each of the three actually allows
Here they are in order of severity, scored on CVSS, the shared 10-point scale.
CVE-2026-59764: commands run from the consumer router's settings screen
This one hits the consumer WRC-X3000GS3-B and GS3A-B. CVE-2026-59764 is a case where input from the settings screen is passed into an internal routine loosely enough that slipping a device command into a form field gets it executed. The class is called OS command injection. Severity 7.2 (8.6 on the newer CVSS 4.0 scale). Reported by Hirofumi Tanabe of Mitsui Bussan Secure Directions.
Execution happens on the router itself, so the reach is the entire home network behind it. Quietly rewrite where traffic is sent and a visitor believing they are on a legitimate site lands on a fake one instead.
CVE-2026-61376: commands run through the business AP's settings-restore feature
This affects the five WAB access points. CVE-2026-61376 is also OS command injection, but through a different door: the "restore settings" function, the one that loads a previously saved configuration file. Plant a command inside that file and it runs as part of the restore. Severity is likewise 7.2 (8.6 on CVSS 4.0). Reported by Rintaro Kawasugi — and this is the one case of the three that went directly to the vendor rather than through Japan's IPA coordination scheme.
Business access points are usually deployed in fleets sharing one configuration. Which means the very practice of distributing configuration files overlaps with this flaw's attack path. If maintenance is outsourced, it is worth asking once how those files reach the devices.
CVE-2026-44387: script execution in the browser of whoever opens the settings screen
Also on the five WAB models, CVE-2026-44387 comes from the settings screen echoing a submitted value back into its output. Get an administrator to open a crafted URL and the attacker's script runs in that administrator's browser. At 5.2 it is the mildest of the three, and it needs both a position on the same network and an administrator who clicks. Reported by Kentaro Ishii of GMO Cybersecurity by Ierae.
How much comfort is "requires a login", really?
Both command-injection flaws carry the condition that the attacker can log in to the settings screen. The natural reaction is "our admin page is not exposed and it has a password, so this is not our problem." Three things complicate that.
First, the strength of the password itself. ELECOM's February 2026 disclosure round included a finding that factory-default administrator passwords were guessable (CVE-2026-24449). Different models from today's, but the point stands: a login requirement is worth nothing if the login is trivially obtained. If a device has never had its password changed since installation, change it while you are updating it.
Second, the attacker may already be inside. A router or AP settings screen is reachable from any machine on the local network. One infected laptop and that barrier is gone. Flaws of this shape are not the way in — they are the tool for consolidating a foothold once someone is in, because owning the network device means seeing and altering everything that flows through it.
Third, some admin panels are deliberately exposed to the internet for remote management. In 2023 Tokyo's Metropolitan Police warned about home routers being reconfigured by attackers and used as relay points for attacks on other organisations. Seven vendors, ELECOM among them, jointly endorsed that advisory.
Who goes after this, and why
For scale: ELECOM is a meaningful presence in Japan's wireless LAN market. Per BCN AWARD 2026, which aggregates retail point-of-sale data, it held third place with 6.8% of units sold in 2025, behind Buffalo at 46.4% and TP-Link at 38.4%. Its share was above 18% around 2018, so the installed base of ELECOM routers still in daily service is substantial.
Nobody attacking a home router cares about the household. The actors here are botnet operators sweeping the world by machine, accumulating whatever devices still carry a known flaw. They want count, not content: individually these are thin connections, but tens of thousands of them add up to real firepower.
What follows a takeover is renting the device out as a firing position against other people, and skimming anything saleable from the traffic crossing it. The first means attacks on companies you have never heard of leaving from your own line. The second means ISP credentials and an inventory of everything on your network.
The awkward part is that a compromised router almost never announces itself. No warning appears, the internet keeps working. At most things feel slightly slow, or the connection drops occasionally — indistinguishable from hardware getting old. On a business access point, everything behind it is quietly in scope.
What actually happened to another brand in the same group
There is a useful case study for "what if I do not update" inside the ELECOM group. To be clear before anything else: none of what follows is about the seven models above. It concerns Logitec — acquired by ELECOM in 2005 — and broadband routers sold roughly between 2009 and 2013. We found no report of any current ELECOM model being attacked.
In November 2017, JPCERT/CC warned that a Mirai variant was spreading across Japan. The peak observed was around 24,000 hosts. Most of the infected devices were Logitec LAN-W300 series broadband routers. The bug used was a 2014 flaw in a third-party component — and fixed firmware had been shipping three to four years before the outbreak.
It did not end there. Japan's National Institute of Information and Communications Technology published measurements in 2021 showing that roughly half of all Mirai-infected hosts then observed in Japan were still those same Logitec routers — 2,118 of 2,126 collected device identifiers. About 1,500 units were cycling through infection and reinfection, six years after the first warnings. A 2022 follow-up recorded an infected unit whose DDoS load knocked out its own connection so often that its IP address changed 14 times in one day.
Going further back, in 2012 a flaw in the Logitec LAN-W300N/R series exposed the admin page to the internet. JPCERT/CC stated plainly at the time that it had confirmed attacks using the vulnerability. By 2013, credentials believed stolen this way were identified as the likely cause of an unauthorised-login incident at a Japanese ISP. In 2015 the police issued a fresh warning about the same devices.
What this history demonstrates is that a network-device flaw persists for as many years as the device goes untouched, fix or no fix. Unlike a PC or a phone, a router that works is a router nobody opens. No exploitation of today's seven models has been reported, and no ELECOM product has ever appeared in CISA's catalogue of vulnerabilities confirmed under attack (KEV). Which is exactly why finishing this while it is quiet is the cheap option.
Checking and updating the firmware
The two consumer models, WRC-X3000GS3-B and GS3A-B, update automatically at factory settings, provided they have internet access. Most households are therefore already on Ver.1.07 or later. To verify, or if you changed that setting, you can check by hand.
Open 192.168.2.1 in a browser and log in as administrator (the default ID is admin; the password is printed on the setup card that shipped with the unit). Then go to the other-settings menu and choose the firmware-update item to see your current version. The router has to be in router mode. ELECOM documents the steps in its firmware-version check guide and the WRC-X3000GS3 user manual.
The five WAB access points are a different matter. If auto-update is disabled, they must be done by hand, and ELECOM provides a per-model download page for each. If you run a fleet, start by counting the units — some will be mounted in ceilings or inside fixtures and awkward to reach. Check the manual for whether settings survive the update, and take a copy of the configuration before you start.
Two things are worth doing alongside. Change the administrator password if any device still has the factory value — otherwise the "requires a login" condition is not protecting you. And confirm the admin screen is not reachable from the internet; if you do not use remote management, turn it off.
Summary
Three vulnerabilities were disclosed across seven ELECOM wireless routers and access points. The serious pair let commands run on the device via the settings screen and the settings-restore function (both CVSS 7.2); the third, at 5.2, needs tighter conditions. Fixed firmware has been available for six to eight weeks already, for every affected model. Nothing has been declared end-of-support.
The two consumer models auto-update at factory settings, so most are already covered. The people who actually need to act are households that disabled auto-update, and organisations running the manually-updated business access points. There are no exploitation reports and no KEV listing. But given that older devices from the same corporate group were still being infected six years after their fix shipped, "later" is the genuinely risky answer here. We will update this article if exploitation or a KEV listing is confirmed.
Sources
- â–¸ ELECOM - firmware update request for certain network products (advisory EL42-098, Japanese)
- â–¸ JVN#56870912 - Multiple vulnerabilities in ELECOM wireless LAN routers and access points
- â–¸ NVD - CVE-2026-59764
- â–¸ NVD - CVE-2026-61376
- â–¸ NVD - CVE-2026-44387
- â–¸ ELECOM - how to update router firmware (document 8203, Japanese)
- â–¸ JPCERT/CC - alert on Mirai variant infections (2017, Japanese)
- â–¸ NICTER Blog - Mirai-infected hosts in Japan and Logitec routers (2021, Japanese)
- â–¸ NICTER Blog - IP churn on Mirai-infected Logitec routers (2022, Japanese)
- â–¸ JPCERT/CC - alert on the Logitec broadband router vulnerability (2012, Japanese)
- â–¸ Tokyo Metropolitan Police - warning on abuse of home routers (Japanese)
- â–¸ BCN AWARD - wireless LAN category unit share (Japanese)

Makoto Horikawa
Backend Engineer / AWS / Django