Junglewise Threat Intelligence

CVE-2026-6059: NEC Aterm Cross-Site Scripting in web management interface

CVE-2026-6059 · Severity: info · CVSS 4.8 · Published 2026-05-25

Executive brief

A security vulnerability exists in the web management interface of NEC Aterm networking devices. An attacker on the same local network could execute malicious scripts in the browser of a legitimate user who is managing the device. This could lead to unauthorized actions being performed on the device or the theft of session information.

Technical details

A cross-site scripting (XSS) vulnerability (CWE-79) exists in the web management interface of NEC Aterm devices. The flaw stems from improper neutralization of user-supplied input during web page generation. An attacker located on the adjacent network can exploit this by inducing a user to access a malicious link or page while interacting with the management console. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized configuration changes. The vulnerability requires user interaction and is reachable via the adjacent network vector.

Affected products

  • NEC Aterm

Timeline

  • 2026-05-25: advisory: Initial disclosure by NEC Corporation

References

Related threats