Executive brief
NEC UNIVERGE IX-R/IX-V is a telecommunications gateway appliance used in enterprise networks. An authentication bypass vulnerability in its web interface allows an attacker to send tampered messages over the internet to execute arbitrary CLI commands on the device, completely circumventing login security and enabling full system compromise.
Technical details
An authentication bypass vulnerability exists in the WebGUI of the UNIVERGE IX-R/IX-V series, where insufficient validation of WebGUI messages allows an unauthenticated attacker to inject and execute arbitrary CLI commands. The vulnerability is exploitable over the network by tampering with WebGUI protocol messages and sending them directly to the device. An attacker does not require valid credentials or user interaction to trigger the flaw. Successful exploitation permits complete command execution with device privileges. Patch availability has not been confirmed from the advisory text.
Affected products
- NEC UNIVERGE IX-R/IX-V
Timeline
- 2026-09-07: disclosed