Description
A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.
Published: 2026-05-25
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a cross‑site scripting vulnerability that allows an attacker to inject and run arbitrary scripts in the web browser of a user who accesses the Aterm web management interface from an adjacent network. Because the injected code executes with the user’s browser privileges, an attacker can steal credentials, manipulate the interface, redirect the user to phishing sites, or perform other malicious client‑side actions. The vulnerability maps to CWE‑79 and is limited to the client side, not allowing direct compromise of the device’s operating system.

Affected Systems

The affected hardware includes several NEC Platforms models: Aterm 19000T12BE, GX621A1, SH621A1, WX11000T12, WX1800HP, WX3000HP2, WX4200D5, WX5400HP, and WX7800T8. Specific firmware or software versions are not listed in the advisory; therefore all listed models should be considered vulnerable until a vendor‑issued fix is released.

Risk and Exploitability

The CVSS score of 4.8 suggests a moderate risk classification. The exploit probability score is not provided, and the vulnerability is not listed in the CISA KEV catalog, indicating that widespread, publicly known exploitation is not yet documented. Attackers must be able to reach the web interface from an adjacent or local network segment, so the exposure is limited to networks that have connectivity to the Aterm management portal. Because the impact is client‑side, the risk to the device itself is low, but user credentials and confidentiality can be compromised for anyone who visits the interface.

Generated by OpenCVE AI on May 25, 2026 at 04:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure firewall or ACL rules to restrict access to the Aterm management interface to trusted IP ranges or subnetworks only.
  • Apply any firmware or software updates released by NEC that address the XSS flaw; if no update is available, contact the vendor for a patch or further guidance.
  • Where updates are unavailable, implement network segmentation and consider deploying a web application firewall or browser‑based content‑security‑policy that blocks or sanitizes user‑supplied script injection attempts.

Generated by OpenCVE AI on May 25, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 25 May 2026 05:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Allowing Arbitrary Browser Script Execution in NEC Aterm Management Interface

Mon, 25 May 2026 03:30:00 +0000

Type Values Removed Values Added
Description A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: NEC

Published:

Updated: 2026-05-25T02:41:19.695Z

Reserved: 2026-04-10T01:20:30.411Z

Link: CVE-2026-6059

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T05:00:12Z

Weaknesses