CVE-2026-16876

Summary

An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.

Affected Software

VendorProductVersion RangeStatus
NEC CorporationUNIVERGE IX-R/IX-VAll versions from Ver1.1 through Ver1.3, All versions from Ver1.4.21 through Ver1.4.28 and Ver1.5.23affected

Weaknesses

  • CWE-306: CWE-306: Missing Authentication for Critical Function

References