Signal is active with 1 mentions in latest observed window
Immediate actions
Patch nec aterm_w1200ex-ms systems immediately
Recommended action window: Monitor and triage in normal cycle
NVD description
Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device information and change the settings via network.
📶【Atermルータに複数脆弱性】
NEC Atermシリーズに、LAN側からの不正アクセスで任意コマンド実行や装置情報取得につながる複数の脆弱性(CVE-2026-4309 ほか)が公表されました。
対象機種はファーム更新を!
#企業公式相互フォロー
Post summary
NEC Aterm routers have multiple CVE‑2026‑4309 related vulnerabilities disclosed, allowing LAN‑side attackers to execute arbitrary commands and obtain device info; firmware updates are advised.
CVE-2026-4309 Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device information and change the settings via network. https://www.cve.org/CVERecord?id=CVE-2026-4309
Post summary
The post discloses a missing‑authorization vulnerability (CVE-2026-4309) in NEC Aterm Series where an attacker can retrieve device info and alter settings over the network.
⚠️ **Vulnerability Alert:** NEC Aterm Series — Multiple Vulnerabilities (CVE-2026-4309, CVE-2026-4619, CVE-2026-4620, CVE-2026-4621, CVE-2026-4622)
📅 **Timeline:** Disclosure: 2026-03-27, Patch: Not Available
🆔 **CVE-2026-4309** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 17.00%
🆔 **CVE-2026-4619** | 📊 CVSS: 6.0 (MEDIUM 🟡) | 📈 EPSS: 17.66%
🆔 **CVE-2026-4620** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72%
🆔 **CVE-2026-4621** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 18.23%
🆔 **CVE-2026-4622** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72%
🛠️ **Exploit Maturity:** Not Available
🫨 **Attack Vectors:**
- Network (remote)
- Some issues require elevated privileges (PR:H)
- OS command injection variants may require user interaction (UI:A)
📝 **Summary:**
Multiple flaws in NEC Aterm devices allow info disclosure, unauthorized config changes, arbitrary file overwrite, and OS command injection that can lead to remote code execution and full device compromise; some issues can also enable telnet. Root causes are insufficient authorization checks and improper input validation—patches are not yet widely available.
📈 **Impact Scope:** Disclosure of device-specific information; unauthorized configuration changes; arbitrary file overwrite; arbitrary OS command execution leading to remote code execution and full device compromise; enabling telnet service increasing exposure. Affects multiple NEC Aterm models (see vendor advisory for model-specific details).
🛡️ **Recommended Actions:**
- Apply vendor-provided patches per model immediately; if unavailable, isolate management interfaces via firewall/VLANs.
- Disable remote management and telnet, change default credentials, inventory devices, backup configs, and monitor logs for suspicious activity.
🪢 **Related Resources:**
- https://jvn.jp/jp/JVN89339669/
- https://jvndb.jvn.jp/jvndb/JVNDB-2026-000049
🏷 **Tags:** #Cybersecurity#NEC#Aterm
Post summary
NEC Aterm devices have multiple newly disclosed vulnerabilities (CVE-2026-4309 to CVE-2026-4622) that enable information disclosure, command injection, and remote code execution, with no patches yet available but mitigations such as network isolation and disabling remote management are recommended.