Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-42948 1 Elecom 4 Wab-be187-m, Wab-be36-m, Wab-be36-s and 1 more 2026-05-17 N/A
Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another administrative user's web browser.
CVE-2026-42950 1 Elecom 4 Wab-be187-m, Wab-be36-m, Wab-be36-s and 1 more 2026-05-17 N/A
ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may become broken.
CVE-2026-42961 1 Elecom 4 Wab-be187-m, Wab-be36-m, Wab-be36-s and 1 more 2026-05-17 N/A
ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.