Authentication Bypass in UNIVERGE IX-R/IX-V by NEC
CVE-2026-16876
9.3CRITICAL
What is CVE-2026-16876?
An authentication bypass flaw is present in the WebGUI of NEC's UNIVERGE IX-R and IX-V series. This vulnerability allows an attacker to circumvent authentication mechanisms, permitting unauthorized execution of arbitrary CLI commands through manipulated WebGUI messages sent over the internet. Ensuring proper validation and security measures is critical to mitigate this risk.
Affected Version(s)
UNIVERGE IX-R/IX-V All versions from Ver1.1 through Ver1.3, All versions from Ver1.4.21 through Ver1.4.28 and Ver1.5.23
