CVE-2026-4622Disclosure(nec / aterm_gb1200pe)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch nec aterm_gb1200pe systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aterm_gb1200pe
  • aterm_gb1200pe_firmware
  • aterm_wf1200cr
  • aterm_wf1200cr_firmware

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-04-04)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
aterm_gb1200peaterm_gb1200pe_firmwareaterm_wf1200craterm_wf1200cr_firmwareaterm_wg1200craterm_wg1200cr_firmwareaterm_wg2600hm4aterm_wg2600hm4_firmwareaterm_wg2600hp4aterm_wg2600hp4_firmware

1 version affected across 18 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-27: 1Mentions · 2026-04-03: 1Mentions · 2026-04-04: 2Patch / Workaround · 2026-04-03: 1Technical Details · 2026-03-27: 1Technical Details · 2026-04-03: 1Technical Details · 2026-04-04: 203-2704-0304-04
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-271
Disclosure1
2026-04-031
Disclosure1
2026-04-042
Disclosure1General1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4622 OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network. https://www.cve.org/CVERecord?id=CVE-2026-4622

    Post summary

    The text announces CVE-2026-4622, labeling it as an OS command injection vulnerability that permits arbitrary commands over the network, but offers no evidence of exploitation or remediation.

    0001066
    56.9K followersView on X
  • floater@floater7
    General

    ・任意のOSコマンドを実行される(CVE-2026-4620/CVE-2026-4622) その時喰らったのが恐らくこれ 自分が管理している端末の接続数が2台オーバーしていた MACアドレス的なやつからPCなのかスマホなのかゲームなのか ひとつひとつ見ていったけど それが結局なんであるかすらもわからなかった

    Post summary

    The post reports an observed arbitrary OS command execution related to CVE-2026-4620/CVE-2026-4622, with no supporting PoC, exploit tool, patch, or claim of active exploitation.

    0000078
    29 followersView on X
  • ほっけタソ@HokkeTaso
    Disclosure

    いろいろヤバすぎる "●想定される影響(一例) ・装置固有の情報を取得され、結果として設定を変更される(CVE-2026-4309) ・任意のファイルを上書きされる(CVE-2026-4619) ・任意のOSコマンドを実行される(CVE-2026-4620/CVE-2026-4622) ・telnetサービスを有効化される(CVE-2026-4621)"

    Post summary

    The post enumerates several CVE-2026 vulnerabilities and summarizes their potential impacts, indicating a disclosure of new security issues without providing PoC, exploit tools, or patches.

    0000060
    2.2K followersView on X
  • Syed Aquib@syedaquib77
    Disclosure

    ⚠️ **Vulnerability Alert:** NEC Aterm Series — Multiple Vulnerabilities (CVE-2026-4309, CVE-2026-4619, CVE-2026-4620, CVE-2026-4621, CVE-2026-4622) 📅 **Timeline:** Disclosure: 2026-03-27, Patch: Not Available 🆔 **CVE-2026-4309** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 17.00% 🆔 **CVE-2026-4619** | 📊 CVSS: 6.0 (MEDIUM 🟡) | 📈 EPSS: 17.66% 🆔 **CVE-2026-4620** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72% 🆔 **CVE-2026-4621** | 📊 CVSS: 6.3 (MEDIUM 🟡) | 📈 EPSS: 18.23% 🆔 **CVE-2026-4622** | 📊 CVSS: 7.1 (HIGH 🟠) | 📈 EPSS: 61.72% 🛠️ **Exploit Maturity:** Not Available 🫨 **Attack Vectors:** - Network (remote) - Some issues require elevated privileges (PR:H) - OS command injection variants may require user interaction (UI:A) 📝 **Summary:** Multiple flaws in NEC Aterm devices allow info disclosure, unauthorized config changes, arbitrary file overwrite, and OS command injection that can lead to remote code execution and full device compromise; some issues can also enable telnet. Root causes are insufficient authorization checks and improper input validation—patches are not yet widely available. 📈 **Impact Scope:** Disclosure of device-specific information; unauthorized configuration changes; arbitrary file overwrite; arbitrary OS command execution leading to remote code execution and full device compromise; enabling telnet service increasing exposure. Affects multiple NEC Aterm models (see vendor advisory for model-specific details). 🛡️ **Recommended Actions:** - Apply vendor-provided patches per model immediately; if unavailable, isolate management interfaces via firewall/VLANs. - Disable remote management and telnet, change default credentials, inventory devices, backup configs, and monitor logs for suspicious activity. 🪢 **Related Resources:** - https://jvn.jp/jp/JVN89339669/ - https://jvndb.jvn.jp/jvndb/JVNDB-2026-000049 🏷 **Tags:** #Cybersecurity #NEC #Aterm

    Post summary

    The post announces multiple newly disclosed vulnerabilities in NEC Aterm devices, provides technical details and mitigation guidance, but lacks evidence of active exploitation or existing PoC/exploit code.

    0000063
    277 followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
HWnecaterm_gb1200pe---
OSnecaterm_gb1200pe_firmware---
HWnecaterm_wf1200cr---
OSnecaterm_wf1200cr_firmware---
HWnecaterm_wg1200cr---
OSnecaterm_wg1200cr_firmware---
HWnecaterm_wg2600hm4---
OSnecaterm_wg2600hm4_firmware---
HWnecaterm_wg2600hp4---
OSnecaterm_wg2600hp4_firmware---
HWnecaterm_wg2600hs---
HWnecaterm_wg2600hs2---
OSnecaterm_wg2600hs2_firmware---
OSnecaterm_wg2600hs_firmware---
HWnecaterm_wx3000hp---
HWnecaterm_wx3000hp2---
OSnecaterm_wx3000hp2_firmware---
OSnecaterm_wx3000hp_firmware---

Explore more