CVE-2026-16876
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
Summary
An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| NEC Corporation | UNIVERGE IX-R/IX-V | All versions from Ver1.1 through Ver1.3, All versions from Ver1.4.21 through Ver1.4.28 and Ver1.5.23 | affected |
Weaknesses
- CWE-306: CWE-306: Missing Authentication for Critical Function
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.