What is CVE-2026-61376?
ELECOM wireless LAN routers and access points contain an OS Command Injection vulnerability in the Restore Settings functionality. An attacker who is able to log in to the affected device can exploit this to execute arbitrary OS commands. Apply the latest firmware updates provided by the vendor to mitigate this vulnerability.
Azərbaycanca: ELECOM simsiz LAN router və giriş nöqtəsi cihazlarında Restore Settings funksiyasında OS Command Injection zəifliyi aşkar edilib. Bu zəiflikdən istifadə edə bilən autentifikasiya olunmuş təcavüzkar, cihazda əməliyyat sistemi səviyyəsində ixtiyari əmrlər icra edə bilər. Cihazlarınızı qorumaq üçün dərhal istehsalçı tərəfindən təqdim edilən ən son proqram təminatı (firmware) yeniləməsini tətbiq edin.
Related CVEs
link basis: same weakness class CWE-78; shared vendor: ELECOM
FAQ2
Which ELECOM devices are affected by CVE-2026-61376?
The vulnerability affects ELECOM wireless LAN routers and access points.
Does the attacker need to be authenticated to exploit CVE-2026-61376?
Yes, an attacker must be able to log in to the affected device to exploit this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.