Executive brief
NEC Aterm networking devices contain a security flaw that allows an attacker to take full control of the underlying operating system. To exploit this, an attacker must first gain administrative access to the device's web management console. Once logged in, they can execute unauthorized commands, potentially leading to data interception, network disruption, or further attacks on the local network.
Technical details
An OS command injection vulnerability (CWE-78) exists within the web-based management console of NEC Aterm devices. The flaw is triggered when the application fails to properly neutralize special elements used in OS commands. An attacker with high privileges (administrator access) can exploit this vulnerability over an adjacent network to execute arbitrary system commands. This could result in a complete compromise of the device's integrity, availability, and confidentiality. The vulnerability was reported by NEC Corporation with a CVSS 4.0 score of 8.5.
Affected products
- NEC Aterm
Timeline
- 2026-05-25: disclosed: Initial publication of CVE-2026-8652 by NEC Corporation.