CVE-2026-4620General(nec / aterm_wx1500hp)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch nec aterm_wx1500hp systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aterm_wx1500hp
  • aterm_wx1500hp_firmware
  • aterm_wx3600hp
  • aterm_wx3600hp_firmware

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-04)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
aterm_wx1500hpaterm_wx1500hp_firmwareaterm_wx3600hpaterm_wx3600hp_firmware

1 version affected across 4 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-27: 1Mentions · 2026-04-03: 1Mentions · 2026-04-04: 2Patch / Workaround · 2026-04-03: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-04: 203-2704-0304-04
Signal classification3 categories
General
250.0%
Disclosure
125.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-04-031
Patch1
2026-04-042
General2
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4620 OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network. https://www.cve.org/CVERecord?id=CVE-2026-4620

    Post summary

    The post announces a new OS command injection vulnerability (CVE‑2026‑4620) in NEC Aterm Series that permits remote execution of arbitrary OS commands.

    0001056
    56.9K followersView on X
  • floater@floater7
    General

    ・任意のOSコマンドを実行される(CVE-2026-4620/CVE-2026-4622) その時喰らったのが恐らくこれ 自分が管理している端末の接続数が2台オーバーしていた MACアドレス的なやつからPCなのかスマホなのかゲームなのか ひとつひとつ見ていったけど それが結局なんであるかすらもわからなかった

    Post summary

    The user reports experiencing an incident likely linked to CVE-2026-4620/4622, which allows arbitrary OS command execution, but provides no evidence of PoC, exploit code, patches, or active exploitation.

    0000078
    29 followersView on X
  • ほっけタソ@HokkeTaso
    General

    いろいろヤバすぎる "●想定される影響(一例) ・装置固有の情報を取得され、結果として設定を変更される(CVE-2026-4309) ・任意のファイルを上書きされる(CVE-2026-4619) ・任意のOSコマンドを実行される(CVE-2026-4620/CVE-2026-4622) ・telnetサービスを有効化される(CVE-2026-4621)"

    Post summary

    The post lists potential impacts for several CVEs but does not provide POc, exploit code, active exploitation evidence, patches, or detailed technical specifics beyond high‑level impact descriptions.

    0000060
    2.2K followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** NEC Aterm Series — Multiple Vulnerabilities (CVE-2026-4309, CVE-2026-4619, CVE-2026-4620, CVE-2026-4621, CVE-2026-4622) 📅 **Timeline:** Disclosure: 2026-03-27, Patch: Not Available 🆔 **CVE-2026-4309** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 17.00% 🆔 **CVE-2026-4619** | 📊 CVSS: 6.0 (MEDIUM 🟡) | 📈 EPSS: 17.66% 🆔 **CVE-2026-4620** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72% 🆔 **CVE-2026-4621** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 18.23% 🆔 **CVE-2026-4622** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72% 🛠️ **Exploit Maturity:** Not Available 🫨 **Attack Vectors:** - Network (remote) - Some issues require elevated privileges (PR:H) - OS command injection variants may require user interaction (UI:A) 📝 **Summary:** Multiple flaws in NEC Aterm devices allow info disclosure, unauthorized config changes, arbitrary file overwrite, and OS command injection that can lead to remote code execution and full device compromise; some issues can also enable telnet. Root causes are insufficient authorization checks and improper input validation—patches are not yet widely available. 📈 **Impact Scope:** Disclosure of device-specific information; unauthorized configuration changes; arbitrary file overwrite; arbitrary OS command execution leading to remote code execution and full device compromise; enabling telnet service increasing exposure. Affects multiple NEC Aterm models (see vendor advisory for model-specific details). 🛡️ **Recommended Actions:** - Apply vendor-provided patches per model immediately; if unavailable, isolate management interfaces via firewall/VLANs. - Disable remote management and telnet, change default credentials, inventory devices, backup configs, and monitor logs for suspicious activity. 🪢 **Related Resources:** - https://jvn.jp/jp/JVN89339669/ - https://jvndb.jvn.jp/jvndb/JVNDB-2026-000049 🏷 **Tags:** #Cybersecurity #NEC #Aterm

    Post summary

    The post outlines multiple CVEs in NEC Aterm devices, provides detailed technical and impact information, and offers mitigation steps, but it does not present proof of exploitation or an active threat.

    0000063
    277 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
HWnecaterm_wx1500hp---
OSnecaterm_wx1500hp_firmware---
HWnecaterm_wx3600hp---
OSnecaterm_wx3600hp_firmware---

Explore more