Impact
The flaw allows an external actor to bypass authentication in the WebGUI of NEC UNIVERGE IX‑R/IX‑V series, enabling them to send crafted messages that are interpreted as direct CLI commands. Once authenticated, the attacker can execute arbitrary commands with the privileges of the device, exposing the system to complete compromise of confidentiality, integrity, and availability. This is catalogued as a CWE‑306 (Missing Authentication for Critical Function). The CVSS base score of 9.3 classifies it as critical.
Affected Systems
Affecting NEC’s UNIVERGE IX‑R and IX‑V appliance lines, the vulnerability is active in all current message handling modules of the WebGUI. No specific firmware versions are listed in the advisory, so systems running the default or legacy images should be considered vulnerable until a patch is applied.
Risk and Exploitability
Because the attack vector is remote over the Internet and requires only the ability to send WebGUI packets, the likelihood of exploitation is high for publicly reachable devices. The EPSS score is not available, but the high CVSS and the absence of mitigations in the public network imply a significant risk. NEC has not listed the issue in CISA’s KEV catalogue, but the critical severity warrants immediate attention.
OpenCVE Enrichment