CVE-2026-16876

9.3

NEC · UNIVERGE IX-R/IX-V

An authentication bypass in the NEC UNIVERGE IX-R/IX-V WebGUI allows unauthenticated remote attackers to execute arbitrary CLI commands via message tampering.

Executive summary

A critical authentication bypass vulnerability in NEC UNIVERGE IX-R/IX-V routers allows unauthenticated remote attackers to execute unauthorized commands, posing a severe risk of system compromise.

Vulnerability

The vulnerability, categorized as CWE-306, stems from missing authentication for critical functions within the device WebGUI. This flaw permits an unauthenticated attacker to inject and execute arbitrary CLI commands by manipulating WebGUI messages sent over the internet.

Business impact

The ability for an unauthenticated user to execute arbitrary commands on networking hardware represents a critical security failure. This vulnerability could lead to a total compromise of the affected device, enabling attackers to intercept traffic, modify network configurations, or pivot into internal infrastructure. Given the CVSS score of 9.3, this issue warrants immediate attention to prevent unauthorized administrative access and potential service disruption.

Remediation

Immediate Action: Review the official NEC security advisory for the latest firmware release and apply the update to all affected UNIVERGE IX-R/IX-V devices as soon as it becomes available.

Proactive Monitoring: Monitor device access logs for unusual administrative activity or unauthorized attempts to access the WebGUI interface from untrusted IP addresses.

Compensating Controls: Restrict access to the WebGUI interface to trusted management networks only and disable remote management over the internet until the patch is applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the critical severity of this vulnerability and the potential for remote command execution, administrators must prioritize identifying all internet-facing UNIVERGE IX-R/IX-V units. Ensure these devices are isolated from direct public internet access immediately and maintain vigilance for vendor-provided firmware updates to fully remediate the underlying authentication flaw.

More NEC CVEs

Sources

Originally found and disclosed by Kojiro Enokida of Sophos Ltd., per the CVE Program record.