Description
Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.
Published: 2026-03-27
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Enable Telnet via Network
Action: Apply Patch
AI Analysis

Impact

A hidden feature in NEC Aterm routers allows an attacker to activate the Telnet service through network traffic. Turning on Telnet exposes a remote command interface that is normally disabled, potentially creating a vector for unauthorized control of the device. The flaw itself is a Remote Service Activation weakness classified as CWE‑912.

Affected Systems

NEC Platforms, Ltd. Aterm Series routers and gateways, including models W1200EX(-MS), WF1200CR, WG1200CR, WG1200HP2, WG1200HP3, WG1200HP4, WG1200HS2, WG1200HS3, WG1200HS4, WG1800HP3, WG1800HP4, WG1900HP, WG1900HP2, WG2600HM4, WG2600HP4, WG2600HS, WG2600HS2, WX1500HP, WX3000HP, WX3000HP2, and WX3600HP. No firmware version is specified, so all updates of these models may carry the vulnerability until the vendor issues a corrective release.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity, implying that activating Telnet can compromise device integrity or confidentiality. Exploit probability data is not provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting no public exploitation has been documented. The likely attack vector is remote over the network, meaning any device exposed to the Internet or an untrusted internal network could be targeted to toggle Telnet on.

Generated by OpenCVE AI on March 27, 2026 at 13:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to the latest NEC Aterm release that addresses the hidden Telnet activation flaw
  • If no update is available, disable the Telnet service in the device configuration and restrict its use to trusted IP addresses
  • Block TCP port 23 (Telnet) at the network perimeter using firewall rules
  • Enable logging for configuration changes and monitor logs for unauthorized attempts to enable Telnet

Generated by OpenCVE AI on March 27, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Nec aterm W1200ex-ms
Nec aterm W1200ex-ms Firmware
Nec aterm Wf1200cr Firmware
Nec aterm Wg1200cr Firmware
Nec aterm Wg1200hp2 Firmware
Nec aterm Wg1200hp3 Firmware
Nec aterm Wg1200hp4 Firmware
Nec aterm Wg1200hs2 Firmware
Nec aterm Wg1200hs3 Firmware
Nec aterm Wg1200hs4 Firmware
Nec aterm Wg1800hp3 Firmware
Nec aterm Wg1800hp4 Firmware
Nec aterm Wg1900hp2 Firmware
Nec aterm Wg1900hp Firmware
Nec aterm Wg2600hm4 Firmware
Nec aterm Wg2600hp4 Firmware
Nec aterm Wg2600hs2 Firmware
Nec aterm Wg2600hs Firmware
Nec aterm Wx1500hp Firmware
Nec aterm Wx3000hp2 Firmware
Nec aterm Wx3000hp Firmware
Nec aterm Wx3600hp Firmware
CPEs cpe:2.3:h:nec:aterm_w1200ex-ms:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wf1200cr:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg1200cr:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg1200hp2:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg1200hp3:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg1200hp4:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg1200hs2:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg1200hs3:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg1200hs4:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg1800hp3:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg1800hp4:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg1900hp2:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg1900hp:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg2600hm4:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg2600hp4:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg2600hs2:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wg2600hs:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wx1500hp:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wx3000hp2:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wx3000hp:-:*:*:*:*:*:*:*
cpe:2.3:h:nec:aterm_wx3600hp:-:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_w1200ex-ms_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wf1200cr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg1200cr_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg1200hp2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg1200hp3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg1200hp4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg1200hs2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg1200hs3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg1200hs4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg1800hp3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg1800hp4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg1900hp2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg1900hp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg2600hm4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg2600hp4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg2600hs2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wg2600hs_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wx1500hp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wx3000hp2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wx3000hp_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:nec:aterm_wx3600hp_firmware:*:*:*:*:*:*:*:*
Vendors & Products Nec aterm W1200ex-ms
Nec aterm W1200ex-ms Firmware
Nec aterm Wf1200cr Firmware
Nec aterm Wg1200cr Firmware
Nec aterm Wg1200hp2 Firmware
Nec aterm Wg1200hp3 Firmware
Nec aterm Wg1200hp4 Firmware
Nec aterm Wg1200hs2 Firmware
Nec aterm Wg1200hs3 Firmware
Nec aterm Wg1200hs4 Firmware
Nec aterm Wg1800hp3 Firmware
Nec aterm Wg1800hp4 Firmware
Nec aterm Wg1900hp2 Firmware
Nec aterm Wg1900hp Firmware
Nec aterm Wg2600hm4 Firmware
Nec aterm Wg2600hp4 Firmware
Nec aterm Wg2600hs2 Firmware
Nec aterm Wg2600hs Firmware
Nec aterm Wx1500hp Firmware
Nec aterm Wx3000hp2 Firmware
Nec aterm Wx3000hp Firmware
Nec aterm Wx3600hp Firmware
Metrics cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Mon, 30 Mar 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Nec
Nec aterm W1200ex(-ms)
Nec aterm Wf1200cr
Nec aterm Wg1200cr
Nec aterm Wg1200hp2
Nec aterm Wg1200hp3
Nec aterm Wg1200hp4
Nec aterm Wg1200hs2
Nec aterm Wg1200hs3
Nec aterm Wg1200hs4
Nec aterm Wg1800hp3
Nec aterm Wg1800hp4
Nec aterm Wg1900hp
Nec aterm Wg1900hp2
Nec aterm Wg2600hm4
Nec aterm Wg2600hp4
Nec aterm Wg2600hs
Nec aterm Wg2600hs2
Nec aterm Wx1500hp
Nec aterm Wx3000hp
Nec aterm Wx3000hp2
Nec aterm Wx3600hp
Vendors & Products Nec
Nec aterm W1200ex(-ms)
Nec aterm Wf1200cr
Nec aterm Wg1200cr
Nec aterm Wg1200hp2
Nec aterm Wg1200hp3
Nec aterm Wg1200hp4
Nec aterm Wg1200hs2
Nec aterm Wg1200hs3
Nec aterm Wg1200hs4
Nec aterm Wg1800hp3
Nec aterm Wg1800hp4
Nec aterm Wg1900hp
Nec aterm Wg1900hp2
Nec aterm Wg2600hm4
Nec aterm Wg2600hp4
Nec aterm Wg2600hs
Nec aterm Wg2600hs2
Nec aterm Wx1500hp
Nec aterm Wx3000hp
Nec aterm Wx3000hp2
Nec aterm Wx3600hp

Fri, 27 Mar 2026 20:30:00 +0000

Type Values Removed Values Added
Title Enable Telnet via Hidden Functionality in NEC Aterm Devices

Fri, 27 Mar 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Mar 2026 12:15:00 +0000

Type Values Removed Values Added
Description Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.
Weaknesses CWE-912
References
Metrics cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Nec Aterm W1200ex(-ms) Aterm W1200ex-ms Aterm W1200ex-ms Firmware Aterm Wf1200cr Aterm Wf1200cr Firmware Aterm Wg1200cr Aterm Wg1200cr Firmware Aterm Wg1200hp2 Aterm Wg1200hp2 Firmware Aterm Wg1200hp3 Aterm Wg1200hp3 Firmware Aterm Wg1200hp4 Aterm Wg1200hp4 Firmware Aterm Wg1200hs2 Aterm Wg1200hs2 Firmware Aterm Wg1200hs3 Aterm Wg1200hs3 Firmware Aterm Wg1200hs4 Aterm Wg1200hs4 Firmware Aterm Wg1800hp3 Aterm Wg1800hp3 Firmware Aterm Wg1800hp4 Aterm Wg1800hp4 Firmware Aterm Wg1900hp Aterm Wg1900hp2 Aterm Wg1900hp2 Firmware Aterm Wg1900hp Firmware Aterm Wg2600hm4 Aterm Wg2600hm4 Firmware Aterm Wg2600hp4 Aterm Wg2600hp4 Firmware Aterm Wg2600hs Aterm Wg2600hs2 Aterm Wg2600hs2 Firmware Aterm Wg2600hs Firmware Aterm Wx1500hp Aterm Wx1500hp Firmware Aterm Wx3000hp Aterm Wx3000hp2 Aterm Wx3000hp2 Firmware Aterm Wx3000hp Firmware Aterm Wx3600hp Aterm Wx3600hp Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: NEC

Published:

Updated: 2026-04-10T04:13:59.147Z

Reserved: 2026-03-23T06:04:48.670Z

Link: CVE-2026-4621

cve-icon Vulnrichment

Updated: 2026-03-27T12:57:28.056Z

cve-icon NVD

Status : Analyzed

Published: 2026-03-27T12:16:20.910

Modified: 2026-04-20T15:20:06.500

Link: CVE-2026-4621

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-30T07:02:08Z

Weaknesses