CVE-2026-50043 Details
Description
Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product with an administrative privilege.
A command injection vulnerability has been identified in the Seiko Solutions SkyBridge MB-A100 and MB-A110 products. This issue allows an attacker with administrative privileges to execute arbitrary operating system commands. The vulnerability exists in all versions of these products.
SkyBridge MB-A100/MB-A110 is no longer supported, and no firmware update will be released to address this vulnerability. Users should change the default administrator password, disable WebUI access, restrict WAN access, and use a closed network. For more details, refer to the information provided by the developer.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 1, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/jp/JVN20721579/ | [email protected] | AdvisoryRemedy |
| https://www.seiko-sol.co.jp/archives/94618/ | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Seiko Solutions SkyBridge MB-A100 | All versions |
CPE
Remediation
| |
| Seiko Solutions SkyBridge MB-A110 | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |
Volerion