Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser.
Metrics
Affected Vendors & Products
References
History
Sun, 17 May 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Elecom
Elecom wab-be187-m Elecom wab-be36-m Elecom wab-be36-s Elecom wab-be72-m |
|
| Vendors & Products |
Elecom
Elecom wab-be187-m Elecom wab-be36-m Elecom wab-be36-s Elecom wab-be72-m |
Wed, 13 May 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 13 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Stored XSS Vulnerability in ELECOM Wireless Access Point Administration Interface |
Wed, 13 May 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser. | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: jpcert
Published: 2026-05-13T12:02:03.914Z
Updated: 2026-05-13T15:06:33.320Z
Reserved: 2026-05-07T05:47:09.922Z
Link: CVE-2026-42948
Updated: 2026-05-13T15:06:27.116Z
Status : Deferred
Published: 2026-05-13T13:16:44.063
Modified: 2026-05-13T15:47:10.327
Link: CVE-2026-42948
No data.
ReportizFlow