CVE-2026-42961: Elecom Co.,ltd Wab-BE187-M
Medium severity, CVSS 5.1. EPSS: 0.3% chance of exploitation in the next 30 days.
ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.
Affected products
- Elecom Co.,ltd Wab-BE187-M: up to and including v1.1.10
- Elecom Co.,ltd Wab-BE36-M: up to and including v1.1.3
- Elecom Co.,ltd Wab-BE36-S: up to and including v1.1.3
- Elecom Co.,ltd Wab-BE72-M: up to and including v1.1.3
Published 2026-05-13. Last modified 2026-06-17.