CVE-2026-42950: Elecom Co.,ltd Wab-BE187-M
Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.
ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken.
Affected products
- Elecom Co.,ltd Wab-BE187-M: up to and including v1.1.10
- Elecom Co.,ltd Wab-BE36-M: up to and including v1.1.3
- Elecom Co.,ltd Wab-BE36-S: up to and including v1.1.3
- Elecom Co.,ltd Wab-BE72-M: up to and including v1.1.3
Published 2026-05-13. Last modified 2026-06-17.