CRITICALCVE-2026-40621Published Modified CNA jpcert
CVE-2026-40621: ELECOM wireless LAN access point devices do not require authentication to access some specific URLs
ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.
Metrics
- CVSS v4.0
- 9.3
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 4
Affected packages
- ELECOM CO.,LTD. / WRC-BE72XSD-Bv1.1.1 and earlier
- ELECOM CO.,LTD. / WRC-BE72XSD-BAv1.1.1 and earlier
- ELECOM CO.,LTD. / WRC-BE65QSD-Bv1.1.0 and earlier
- ELECOM CO.,LTD. / WRC-W702-Bv1.1.0 and earlier
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NReferences