What is CVE-2026-59764?
An OS Command Injection vulnerability has been identified in the WebUI of ELECOM wireless LAN routers and access points. An attacker who can log in to the affected product may exploit this to execute arbitrary OS commands. It is recommended to isolate the device from the network and apply the vendor's security update.
Azərbaycanca: ELECOM simsiz LAN marşrutlaşdırıcı və giriş nöqtələrində WebUI vasitəsilə OS Command Injection zəifliyi aşkarlanıb. Bu zəiflikdən istifadə edən və məhsula daxil ola bilən hücumçu ixtiyari əməliyyat sistemi əmri icra edə bilər. Cihazı şəbəkədən təcrid etmək və istehsalçının təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: ELECOM
FAQ2
What does an attacker need to do to exploit CVE-2026-59764?
The attacker must be able to log in to the affected product. The vulnerability allows OS Command Injection via the WebUI.
What security measures are recommended for the affected ELECOM devices?
It is recommended to isolate the device from the network and apply the vendor's security update.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.