Remote Command Execution Vulnerability in NEC Aterm Routers
CVE-2025-0356

4.8MEDIUM

Key Information:

Vendor
Nec Corporation
Status
Wx1500HP
Wx3600HP
Vendor
CVE Published:
15 January 2025

Summary

NEC Corporation's Aterm WX1500HP and WX3600HP routers are susceptible to a remote command execution vulnerability. This flaw allows attackers to execute arbitrary operating system commands by sending crafted requests over the internet, potentially compromising device integrity and security. Users of version 1.4.2 and earlier for the WX1500HP and version 1.5.3 and earlier for the WX3600HP are at risk and should apply necessary patches immediately.

Affected Version(s)

WX1500HP Ver.1.4.2 and earlier

WX3600HP Ver.1.5.3 and earlier

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kakeru Kajihara of NTT Security Holdings.
.