CVE-2026-42961CWE-344

ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens

Medium · published May 13, 2026

CVSS v4.0
5.1
EPSS
0%
Percentile
8.3
In the wild
Unconfirmed
What it is

ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to do unintended operations.

The record
Technical detail
CVSS v4.0
5.1 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS
0.00186 · 8.3th percentile
Weakness
CWE-344 · Use of Invariant Value in Dynamically Changing Context
Published
2026-05-13T12:02Z
EPSS history
Timeline
  • 13 MAY 12:02Z
    ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens
    cvelistv5