An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.
History

Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Nec
Nec univerge Ix
Vendors & Products Nec
Nec univerge Ix

Mon, 07 Sep 2026 03:15:00 +0000

Type Values Removed Values Added
Title WebGUI Authentication Bypass Allows Remote CLI Execution on NEC UNIVERGE IX‑R/IX‑V

Mon, 07 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NEC

Published: 2026-09-07T00:48:01.015Z

Updated: 2026-09-08T15:32:48.460Z

Reserved: 2026-07-24T04:35:25.244Z

Link: CVE-2026-16876

cve-icon Vulnrichment

Updated: 2026-09-08T15:32:29.759Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T02:17:17.630

Modified: 2026-09-09T16:04:24.933

Link: CVE-2026-16876

cve-icon Redhat

No data.