CVE-2026-4621Disclosure(nec / aterm_w1200ex-ms)

LOWCVSS 5.6 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nec aterm_w1200ex-ms systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-912

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aterm_w1200ex-ms
  • aterm_w1200ex-ms_firmware
  • aterm_wf1200cr
  • aterm_wf1200cr_firmware

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-03-27); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
aterm_w1200ex-msaterm_w1200ex-ms_firmwareaterm_wf1200craterm_wf1200cr_firmwareaterm_wg1200craterm_wg1200cr_firmwareaterm_wg1200hp2aterm_wg1200hp2_firmwareaterm_wg1200hp3aterm_wg1200hp3_firmware

1 version affected across 42 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-03-27: 1Mentions · 2026-04-03: 1Mentions · 2026-04-04: 1Mentions · 2026-04-08: 1Patch / Workaround · 2026-04-03: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-04: 103-2704-0304-0404-08
Signal classification2 categories
Disclosure
250.0%
General
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-04-031
Disclosure1
2026-04-041
General1
2026-04-081
General1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4621 Hidden Functionality vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to enable telnet via network. https://www.cve.org/CVERecord?id=CVE-2026-4621

    Post summary

    The post announces CVE-2026-4621 as a hidden functionality flaw in NEC Aterm Series that lets attackers enable telnet, but offers no evidence of exploitation, PoC, or patch details.

    0001085
    56.9K followersView on X
  • びばのん/馬鹿家元@vivanon_iemoto
    General

    秘密のバックドアを仕込むのは、中共だけの習性ではないのだ。 >セキュリティ上問題のある隠し機能(CVE-2026-4621)

    Post summary

    The message merely references CVE-2026-4621 without additional technical detail, exploit information, or mitigation advice.

    00000144
    1.8K followersView on X
  • ほっけタソ@HokkeTaso
    General

    いろいろヤバすぎる "●想定される影響(一例) ・装置固有の情報を取得され、結果として設定を変更される(CVE-2026-4309) ・任意のファイルを上書きされる(CVE-2026-4619) ・任意のOSコマンドを実行される(CVE-2026-4620/CVE-2026-4622) ・telnetサービスを有効化される(CVE-2026-4621)"

    Post summary

    The post enumerates potential impacts for several CVEs without providing PoC, exploit details, patch information, or evidence of active exploitation.

    0000060
    2.2K followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** NEC Aterm Series — Multiple Vulnerabilities (CVE-2026-4309, CVE-2026-4619, CVE-2026-4620, CVE-2026-4621, CVE-2026-4622) 📅 **Timeline:** Disclosure: 2026-03-27, Patch: Not Available 🆔 **CVE-2026-4309** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 17.00% 🆔 **CVE-2026-4619** | 📊 CVSS: 6.0 (MEDIUM 🟡) | 📈 EPSS: 17.66% 🆔 **CVE-2026-4620** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72% 🆔 **CVE-2026-4621** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 18.23% 🆔 **CVE-2026-4622** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72% 🛠️ **Exploit Maturity:** Not Available 🫨 **Attack Vectors:** - Network (remote) - Some issues require elevated privileges (PR:H) - OS command injection variants may require user interaction (UI:A) 📝 **Summary:** Multiple flaws in NEC Aterm devices allow info disclosure, unauthorized config changes, arbitrary file overwrite, and OS command injection that can lead to remote code execution and full device compromise; some issues can also enable telnet. Root causes are insufficient authorization checks and improper input validation—patches are not yet widely available. 📈 **Impact Scope:** Disclosure of device-specific information; unauthorized configuration changes; arbitrary file overwrite; arbitrary OS command execution leading to remote code execution and full device compromise; enabling telnet service increasing exposure. Affects multiple NEC Aterm models (see vendor advisory for model-specific details). 🛡️ **Recommended Actions:** - Apply vendor-provided patches per model immediately; if unavailable, isolate management interfaces via firewall/VLANs. - Disable remote management and telnet, change default credentials, inventory devices, backup configs, and monitor logs for suspicious activity. 🪢 **Related Resources:** - https://jvn.jp/jp/JVN89339669/ - https://jvndb.jvn.jp/jvndb/JVNDB-2026-000049 🏷 **Tags:** #Cybersecurity #NEC #Aterm

    Post summary

    NEC Aterm devices are affected by five CVEs enabling information disclosure, file overwrite, and remote code execution; no patch is available yet, so the recommended mitigations include disabling remote management, isolating interfaces, and enforcing credential changes.

    0000063
    277 followersView on X
CPE platform detail42 entries

42 of 42 entries

PartVendorProductVersionTarget SWTarget HW
HWnecaterm_w1200ex-ms---
OSnecaterm_w1200ex-ms_firmware---
HWnecaterm_wf1200cr---
OSnecaterm_wf1200cr_firmware---
HWnecaterm_wg1200cr---
OSnecaterm_wg1200cr_firmware---
HWnecaterm_wg1200hp2---
OSnecaterm_wg1200hp2_firmware---
HWnecaterm_wg1200hp3---
OSnecaterm_wg1200hp3_firmware---
HWnecaterm_wg1200hp4---
OSnecaterm_wg1200hp4_firmware---
HWnecaterm_wg1200hs2---
OSnecaterm_wg1200hs2_firmware---
HWnecaterm_wg1200hs3---
OSnecaterm_wg1200hs3_firmware---
HWnecaterm_wg1200hs4---
OSnecaterm_wg1200hs4_firmware---
HWnecaterm_wg1800hp3---
OSnecaterm_wg1800hp3_firmware---
HWnecaterm_wg1800hp4---
OSnecaterm_wg1800hp4_firmware---
HWnecaterm_wg1900hp---
HWnecaterm_wg1900hp2---
OSnecaterm_wg1900hp2_firmware---
OSnecaterm_wg1900hp_firmware---
HWnecaterm_wg2600hm4---
OSnecaterm_wg2600hm4_firmware---
HWnecaterm_wg2600hp4---
OSnecaterm_wg2600hp4_firmware---
HWnecaterm_wg2600hs---
HWnecaterm_wg2600hs2---
OSnecaterm_wg2600hs2_firmware---
OSnecaterm_wg2600hs_firmware---
HWnecaterm_wx1500hp---
OSnecaterm_wx1500hp_firmware---
HWnecaterm_wx3000hp---
HWnecaterm_wx3000hp2---
OSnecaterm_wx3000hp2_firmware---
OSnecaterm_wx3000hp_firmware---
HWnecaterm_wx3600hp---
OSnecaterm_wx3600hp_firmware---

Explore more