Description
A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.
Published: 2026-05-25
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a cross‑site scripting vulnerability that allows an attacker to inject and run arbitrary scripts in the web browser of a user who accesses the Aterm web management interface from an adjacent network. Because the injected code executes with the user’s browser privileges, an attacker can steal credentials, manipulate the interface, redirect the user to phishing sites, or perform other malicious client‑side actions. The vulnerability maps to CWE‑79 and is limited to the client side, not allowing direct compromise of the device’s operating system.

Affected Systems

The affected hardware includes several NEC Platforms models: Aterm 19000T12BE, GX621A1, SH621A1, WX11000T12, WX1800HP, WX3000HP2, WX4200D5, WX5400HP, and WX7800T8. Specific firmware or software versions are not listed in the advisory; therefore all listed models should be considered vulnerable until a vendor‑issued fix is released.

Risk and Exploitability

The CVSS score of 4.8 suggests a moderate risk classification. The exploit probability score is not provided, and the vulnerability is not listed in the CISA KEV catalog, indicating that widespread, publicly known exploitation is not yet documented. Attackers must be able to reach the web interface from an adjacent or local network segment, so the exposure is limited to networks that have connectivity to the Aterm management portal. Because the impact is client‑side, the risk to the device itself is low, but user credentials and confidentiality can be compromised for anyone who visits the interface.

Generated by OpenCVE AI on May 25, 2026 at 04:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Configure firewall or ACL rules to restrict access to the Aterm management interface to trusted IP ranges or subnetworks only.
  • Apply any firmware or software updates released by NEC that address the XSS flaw; if no update is available, contact the vendor for a patch or further guidance.
  • Where updates are unavailable, implement network segmentation and consider deploying a web application firewall or browser‑based content‑security‑policy that blocks or sanitizes user‑supplied script injection attempts.

Generated by OpenCVE AI on May 25, 2026 at 04:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 26 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 May 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Necplatforms
Necplatforms aterm 19000t12be
Necplatforms aterm Gx621a1
Necplatforms aterm Sh621a1
Necplatforms aterm Wx11000t12
Necplatforms aterm Wx1800hp
Necplatforms aterm Wx3000hp2
Necplatforms aterm Wx4200d5
Necplatforms aterm Wx5400hp
Necplatforms aterm Wx7800t8
Vendors & Products Necplatforms
Necplatforms aterm 19000t12be
Necplatforms aterm Gx621a1
Necplatforms aterm Sh621a1
Necplatforms aterm Wx11000t12
Necplatforms aterm Wx1800hp
Necplatforms aterm Wx3000hp2
Necplatforms aterm Wx4200d5
Necplatforms aterm Wx5400hp
Necplatforms aterm Wx7800t8

Mon, 25 May 2026 05:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Allowing Arbitrary Browser Script Execution in NEC Aterm Management Interface

Mon, 25 May 2026 03:30:00 +0000

Type Values Removed Values Added
Description A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Necplatforms Aterm 19000t12be Aterm Gx621a1 Aterm Sh621a1 Aterm Wx11000t12 Aterm Wx1800hp Aterm Wx3000hp2 Aterm Wx4200d5 Aterm Wx5400hp Aterm Wx7800t8
cve-icon MITRE

Status: PUBLISHED

Assigner: NEC

Published:

Updated: 2026-05-26T14:44:05.754Z

Reserved: 2026-04-10T01:20:30.411Z

Link: CVE-2026-6059

cve-icon Vulnrichment

Updated: 2026-05-26T14:44:00.184Z

cve-icon NVD

Status : Deferred

Published: 2026-05-25T04:16:25.030

Modified: 2026-05-26T20:14:49.350

Link: CVE-2026-6059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-25T11:33:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')