⚠️ **Vulnerability Alert:** NEC Aterm Series — Multiple Vulnerabilities (CVE-2026-4309, CVE-2026-4619, CVE-2026-4620, CVE-2026-4621, CVE-2026-4622)
📅 **Timeline:** Disclosure: 2026-03-27, Patch: Not Available
🆔 **CVE-2026-4309** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 17.00%
🆔 **CVE-2026-4619** | 📊 CVSS: 6.0 (MEDIUM 🟡) | 📈 EPSS: 17.66%
🆔 **CVE-2026-4620** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72%
🆔 **CVE-2026-4621** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 18.23%
🆔 **CVE-2026-4622** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72%
🛠️ **Exploit Maturity:** Not Available
🫨 **Attack Vectors:**
- Network (remote)
- Some issues require elevated privileges (PR:H)
- OS command injection variants may require user interaction (UI:A)
📝 **Summary:**
Multiple flaws in NEC Aterm devices allow info disclosure, unauthorized config changes, arbitrary file overwrite, and OS command injection that can lead to remote code execution and full device compromise; some issues can also enable telnet. Root causes are insufficient authorization checks and improper input validation—patches are not yet widely available.
📈 **Impact Scope:** Disclosure of device-specific information; unauthorized configuration changes; arbitrary file overwrite; arbitrary OS command execution leading to remote code execution and full device compromise; enabling telnet service increasing exposure. Affects multiple NEC Aterm models (see vendor advisory for model-specific details).
🛡️ **Recommended Actions:**
- Apply vendor-provided patches per model immediately; if unavailable, isolate management interfaces via firewall/VLANs.
- Disable remote management and telnet, change default credentials, inventory devices, backup configs, and monitor logs for suspicious activity.
🪢 **Related Resources:**
- https://jvn.jp/jp/JVN89339669/
- https://jvndb.jvn.jp/jvndb/JVNDB-2026-000049
🏷 **Tags:** #Cybersecurity#NEC#Aterm
Post summary
The text announces multiple newly disclosed vulnerabilities in NEC Aterm devices, detailing severity, impact, and recommended mitigation steps, while noting that patches are currently unavailable.
CVE-2026-4619 Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network. https://www.cve.org/CVERecord?id=CVE-2026-4619
Post summary
CVE-2026-4619 is a Path Traversal vulnerability in NEC Platforms’ Aterm Series that permits an attacker to overwrite any file over the network.