CVE-2026-4619Disclosure(nec / aterm_wx3600hp)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nec aterm_wx3600hp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aterm_wx3600hp
  • aterm_wx3600hp_firmware

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-27); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
aterm_wx3600hpaterm_wx3600hp_firmware

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-27: 1Mentions · 2026-04-03: 1Mentions · 2026-04-04: 1Patch / Workaround · 2026-04-03: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-03: 103-2704-0304-04
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-04-031
Disclosure1
2026-04-041
General1
Full discourse3 posts
  • ほっけタソ@HokkeTaso
    General

    いろいろヤバすぎる "●想定される影響(一例) ・装置固有の情報を取得され、結果として設定を変更される(CVE-2026-4309) ・任意のファイルを上書きされる(CVE-2026-4619) ・任意のOSコマンドを実行される(CVE-2026-4620/CVE-2026-4622) ・telnetサービスを有効化される(CVE-2026-4621)"

    Post summary

    The text lists potential impacts for four CVE-2026 entries, but provides no further technical details, PoC references, or exploitation evidence.

    0000060
    2.2K followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** NEC Aterm Series — Multiple Vulnerabilities (CVE-2026-4309, CVE-2026-4619, CVE-2026-4620, CVE-2026-4621, CVE-2026-4622) 📅 **Timeline:** Disclosure: 2026-03-27, Patch: Not Available 🆔 **CVE-2026-4309** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 17.00% 🆔 **CVE-2026-4619** | 📊 CVSS: 6.0 (MEDIUM 🟡) | 📈 EPSS: 17.66% 🆔 **CVE-2026-4620** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72% 🆔 **CVE-2026-4621** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 18.23% 🆔 **CVE-2026-4622** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72% 🛠️ **Exploit Maturity:** Not Available 🫨 **Attack Vectors:** - Network (remote) - Some issues require elevated privileges (PR:H) - OS command injection variants may require user interaction (UI:A) 📝 **Summary:** Multiple flaws in NEC Aterm devices allow info disclosure, unauthorized config changes, arbitrary file overwrite, and OS command injection that can lead to remote code execution and full device compromise; some issues can also enable telnet. Root causes are insufficient authorization checks and improper input validation—patches are not yet widely available. 📈 **Impact Scope:** Disclosure of device-specific information; unauthorized configuration changes; arbitrary file overwrite; arbitrary OS command execution leading to remote code execution and full device compromise; enabling telnet service increasing exposure. Affects multiple NEC Aterm models (see vendor advisory for model-specific details). 🛡️ **Recommended Actions:** - Apply vendor-provided patches per model immediately; if unavailable, isolate management interfaces via firewall/VLANs. - Disable remote management and telnet, change default credentials, inventory devices, backup configs, and monitor logs for suspicious activity. 🪢 **Related Resources:** - https://jvn.jp/jp/JVN89339669/ - https://jvndb.jvn.jp/jvndb/JVNDB-2026-000049 🏷 **Tags:** #Cybersecurity #NEC #Aterm

    Post summary

    The text announces multiple newly disclosed vulnerabilities in NEC Aterm devices, detailing severity, impact, and recommended mitigation steps, while noting that patches are currently unavailable.

    0000063
    277 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4619 Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network. https://www.cve.org/CVERecord?id=CVE-2026-4619

    Post summary

    CVE-2026-4619 is a Path Traversal vulnerability in NEC Platforms’ Aterm Series that permits an attacker to overwrite any file over the network.

    0000061
    56.9K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWnecaterm_wx3600hp---
OSnecaterm_wx3600hp_firmware---

Explore more