CVE-2026-42948 PUBLISHED

Assigner: jpcert
Reserved: 07.05.2026 Published: 13.05.2026 Updated: 13.05.2026

Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 4.8

Product Status

Vendor ELECOM CO.,LTD.
Product WAB-BE187-M
Versions
  • Version v1.1.10 and earlier is affected
Vendor ELECOM CO.,LTD.
Product WAB-BE72-M
Versions
  • Version v1.1.3 and earlier is affected
Vendor ELECOM CO.,LTD.
Product WAB-BE36-M
Versions
  • Version v1.1.3 and earlier is affected
Vendor ELECOM CO.,LTD.
Product WAB-BE36-S
Versions
  • Version v1.1.3 and earlier is affected

References

Problem Types