CVE-2026-40621

CRITICAL

Elecom Co.,ltd. WRC-BE72XSD-B - Authentication Bypass Using an Alternate Path or Channel

Title source: rule
STIX 2.1

Description

ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.

Scores

CVSS v3 9.8
EPSS 0.0049
EPSS Percentile 38.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-288
Status published
Products (4)
ELECOM CO.,LTD./WRC-BE65QSD-B v1.1.0 and earlier
ELECOM CO.,LTD./WRC-BE72XSD-B v1.1.1 and earlier
ELECOM CO.,LTD./WRC-BE72XSD-BA v1.1.1 and earlier
ELECOM CO.,LTD./WRC-W702-B v1.1.0 and earlier
Published May 13, 2026
Tracked Since May 13, 2026