What is CVE-2026-44387?
A reflected cross-site scripting vulnerability exists in the WebUI of ELECOM wireless LAN routers and access points. If exploited, this could allow an attacker to execute arbitrary scripts in the browser of a logged-in user. It is recommended to apply the security update provided by the vendor.
Azərbaycanca: ELECOM simsiz LAN router və giriş nöqtələrinin veb interfeysində aşkarlanmış reflected cross-site scripting zəifliyidir. Zəiflikdən istifadə edildikdə, təcavüzkar istifadəçinin brauzerində özbaşına skript icra edə bilər. İstehsalçının təqdim etdiyi təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which ELECOM devices are affected by CVE-2026-44387?
The vulnerability exists in the WebUI of ELECOM wireless LAN routers and access points.
What should be done to protect against the CVE-2026-44387 reflected cross-site scripting vulnerability?
It is recommended to apply the security update provided by the vendor ELECOM.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.