CVE-2026-4309Disclosure(nec / aterm_w1200ex-ms)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nec aterm_w1200ex-ms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device information and change the settings via network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aterm_w1200ex-ms
  • aterm_w1200ex-ms_firmware
  • aterm_wf1200cr
  • aterm_wf1200cr_firmware

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-03-27); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
aterm_w1200ex-msaterm_w1200ex-ms_firmwareaterm_wf1200craterm_wf1200cr_firmwareaterm_wg1200craterm_wg1200cr_firmwareaterm_wg1200hp2aterm_wg1200hp2_firmwareaterm_wg1200hp3aterm_wg1200hp3_firmware

1 version affected across 40 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-27: 1Mentions · 2026-04-03: 1Mentions · 2026-04-04: 1Mentions · 2026-04-06: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-06: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-04: 1Technical Details · 2026-04-06: 103-2704-0304-0404-06
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-04-031
Disclosure1
2026-04-041
General1
2026-04-061
Disclosure1
Full discourse4 posts
  • インフォセキュアソリューションズ株式会社@InSecSol0417
    Disclosure

    📶【Atermルータに複数脆弱性】 NEC Atermシリーズに、LAN側からの不正アクセスで任意コマンド実行や装置情報取得につながる複数の脆弱性(CVE-2026-4309 ほか)が公表されました。 対象機種はファーム更新を! #企業公式相互フォロー

    Post summary

    NEC Aterm routers have multiple CVE‑2026‑4309 related vulnerabilities disclosed, allowing LAN‑side attackers to execute arbitrary commands and obtain device info; firmware updates are advised.

    010140255
    536 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4309 Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device information and change the settings via network. https://www.cve.org/CVERecord?id=CVE-2026-4309

    Post summary

    The post discloses a missing‑authorization vulnerability (CVE-2026-4309) in NEC Aterm Series where an attacker can retrieve device info and alter settings over the network.

    00010124
    56.9K followersView on X
  • ほっけタソ@HokkeTaso
    General

    いろいろヤバすぎる "●想定される影響(一例) ・装置固有の情報を取得され、結果として設定を変更される(CVE-2026-4309) ・任意のファイルを上書きされる(CVE-2026-4619) ・任意のOSコマンドを実行される(CVE-2026-4620/CVE-2026-4622) ・telnetサービスを有効化される(CVE-2026-4621)"

    Post summary

    The post enumerates potential effects for a series of CVE‑2026 vulnerabilities but offers no further detail on exploitation, patches, or PoC.

    0000060
    2.2K followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** NEC Aterm Series — Multiple Vulnerabilities (CVE-2026-4309, CVE-2026-4619, CVE-2026-4620, CVE-2026-4621, CVE-2026-4622) 📅 **Timeline:** Disclosure: 2026-03-27, Patch: Not Available 🆔 **CVE-2026-4309** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 17.00% 🆔 **CVE-2026-4619** | 📊 CVSS: 6.0 (MEDIUM 🟡) | 📈 EPSS: 17.66% 🆔 **CVE-2026-4620** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72% 🆔 **CVE-2026-4621** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 18.23% 🆔 **CVE-2026-4622** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72% 🛠️ **Exploit Maturity:** Not Available 🫨 **Attack Vectors:** - Network (remote) - Some issues require elevated privileges (PR:H) - OS command injection variants may require user interaction (UI:A) 📝 **Summary:** Multiple flaws in NEC Aterm devices allow info disclosure, unauthorized config changes, arbitrary file overwrite, and OS command injection that can lead to remote code execution and full device compromise; some issues can also enable telnet. Root causes are insufficient authorization checks and improper input validation—patches are not yet widely available. 📈 **Impact Scope:** Disclosure of device-specific information; unauthorized configuration changes; arbitrary file overwrite; arbitrary OS command execution leading to remote code execution and full device compromise; enabling telnet service increasing exposure. Affects multiple NEC Aterm models (see vendor advisory for model-specific details). 🛡️ **Recommended Actions:** - Apply vendor-provided patches per model immediately; if unavailable, isolate management interfaces via firewall/VLANs. - Disable remote management and telnet, change default credentials, inventory devices, backup configs, and monitor logs for suspicious activity. 🪢 **Related Resources:** - https://jvn.jp/jp/JVN89339669/ - https://jvndb.jvn.jp/jvndb/JVNDB-2026-000049 🏷 **Tags:** #Cybersecurity #NEC #Aterm

    Post summary

    NEC Aterm devices have multiple newly disclosed vulnerabilities (CVE-2026-4309 to CVE-2026-4622) that enable information disclosure, command injection, and remote code execution, with no patches yet available but mitigations such as network isolation and disabling remote management are recommended.

    0000063
    277 followersView on X
CPE platform detail40 entries

40 of 40 entries

PartVendorProductVersionTarget SWTarget HW
HWnecaterm_w1200ex-ms---
OSnecaterm_w1200ex-ms_firmware---
HWnecaterm_wf1200cr---
OSnecaterm_wf1200cr_firmware---
HWnecaterm_wg1200cr---
OSnecaterm_wg1200cr_firmware---
HWnecaterm_wg1200hp2---
OSnecaterm_wg1200hp2_firmware---
HWnecaterm_wg1200hp3---
OSnecaterm_wg1200hp3_firmware---
HWnecaterm_wg1200hp4---
OSnecaterm_wg1200hp4_firmware---
HWnecaterm_wg1200hs2---
OSnecaterm_wg1200hs2_firmware---
HWnecaterm_wg1200hs3---
OSnecaterm_wg1200hs3_firmware---
HWnecaterm_wg1200hs4---
OSnecaterm_wg1200hs4_firmware---
HWnecaterm_wg1800hp3---
OSnecaterm_wg1800hp3_firmware---
HWnecaterm_wg1800hp4---
OSnecaterm_wg1800hp4_firmware---
HWnecaterm_wg1900hp---
HWnecaterm_wg1900hp2---
OSnecaterm_wg1900hp2_firmware---
OSnecaterm_wg1900hp_firmware---
HWnecaterm_wg2600hm4---
OSnecaterm_wg2600hm4_firmware---
HWnecaterm_wg2600hp4---
OSnecaterm_wg2600hp4_firmware---
HWnecaterm_wg2600hs---
HWnecaterm_wg2600hs2---
OSnecaterm_wg2600hs2_firmware---
OSnecaterm_wg2600hs_firmware---
HWnecaterm_wx1500hp---
OSnecaterm_wx1500hp_firmware---
HWnecaterm_wx3000hp---
OSnecaterm_wx3000hp_firmware---
HWnecaterm_wx3600hp---
OSnecaterm_wx3600hp_firmware---

Explore more