An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjacent network.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://jpn.nec.com/security-info/secinfo/nv26-003_en.html |
|
History
Mon, 25 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Necplatforms
Necplatforms aterm Cm51fd Necplatforms aterm Mr51fn |
|
| Vendors & Products |
Necplatforms
Necplatforms aterm Cm51fd Necplatforms aterm Mr51fn |
Mon, 25 May 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Command Injection Vulnerability in NEC Aterm Web Console |
Mon, 25 May 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjacent network. | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: NEC
Published:
Updated: 2026-05-25T02:40:41.776Z
Reserved: 2026-05-15T04:57:29.637Z
Link: CVE-2026-8652
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-05-25T11:33:04Z
Weaknesses