UNIVERGE IX-R/IX-V series routers provided by NEC Corporation contain a missing authentication for critical function vulnerability.
- UNIVERGE IX-R/IX-V series
- Ver1.1 to Ver1.3
- Ver1.4.21 to Ver1.4.28
- Ver1.5.23
UNIVERGE IX-R/IX-V series routers provided by NEC Corporation contain the following vulnerability.
- Missing authentication for critical function (CWE-306)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N Base Score 9.3
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Base Score 9.4
- CVE-2026-16876
If a remote unauthenticated attacker sends a specially crafted message to the WebGUI of the affected product, an arbitrary command may be executed without authentication.
Update the software
Apply the appropriate update according to the information provided by the developer.
Apply the workaround
Disable the affected product's WebGUI if the update cannot be applied.
For more details, refer to the information provided by the developer.
| Vendor | Status | Last Update | Vendor Notes |
|---|---|---|---|
| NEC Corporation | Vulnerable | 2026/08/21 |
Kojiro Enokida of SOPHOS reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
|
| JVN iPedia |
JVNDB-2026-000119 |