Published:2026/08/21  Last Updated:2026/08/21

JVN#81414813
UNIVERGE IX-R/IX-V series routers vulnerable to missing authentication for critical function

Overview

UNIVERGE IX-R/IX-V series routers provided by NEC Corporation contain a missing authentication for critical function vulnerability.

Products Affected

  • UNIVERGE IX-R/IX-V series
    • Ver1.1 to Ver1.3
    • Ver1.4.21 to Ver1.4.28
    • Ver1.5.23
As for the details of affected product names and versions, refer to the information provided by the developer.

Description

UNIVERGE IX-R/IX-V series routers provided by NEC Corporation contain the following vulnerability.

  • Missing authentication for critical function (CWE-306)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N Base Score 9.3
    • CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Base Score 9.4
    • CVE-2026-16876

Impact

If a remote unauthenticated attacker sends a specially crafted message to the WebGUI of the affected product, an arbitrary command may be executed without authentication.

Solution

Update the software
Apply the appropriate update according to the information provided by the developer.

Apply the workaround
Disable the affected product's WebGUI if the update cannot be applied.

For more details, refer to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
NEC Corporation Vulnerable 2026/08/21

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Kojiro Enokida of SOPHOS reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia JVNDB-2026-000119