JVN#81414813
UNIVERGE IX-R/IX-V series routers vulnerable to missing authentication for critical function
Overview
UNIVERGE IX-R/IX-V series routers provided by NEC Corporation contain a missing authentication for critical function vulnerability.
Products Affected
- UNIVERGE IX-R/IX-V series
- Ver1.1 to Ver1.3
- Ver1.4.21 to Ver1.4.28
- Ver1.5.23
Description
UNIVERGE IX-R/IX-V series routers provided by NEC Corporation contain the following vulnerability.
- Missing authentication for critical function (CWE-306)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N Base Score 9.3
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Base Score 9.4
- CVE-2026-16876
Impact
If a remote unauthenticated attacker sends a specially crafted message to the WebGUI of the affected product, an arbitrary command may be executed without authentication.
Solution
Update the software
Apply the appropriate update according to the information provided by the developer.
Apply the workaround
Disable the affected product's WebGUI if the update cannot be applied.
For more details, refer to the information provided by the developer.
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Kojiro Enokida of SOPHOS reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
|
| JVN iPedia |
JVNDB-2026-000119 |