[Japanese]

JVNDB-2026-000119

UNIVERGE IX-R/IX-V series routers vulnerable to missing authentication for critical function

Overview

UNIVERGE IX-R/IX-V series routers provided by NEC Corporation contain the following vulnerability.
  • Missing authentication for critical function (CWE-306) - CVE-2026-16876
Kojiro Enokida of SOPHOS reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 9.4 (Critical) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: Low
CVSS v4 Severity
Base Metrics: 9.3 (Critical) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): None
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): High
  • Integrity Impact (VI): High
  • Availability Impact (VA): Low
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
Affected Products


NEC Corporation
  • UNIVERGE IX-R/IX-V series Ver1.1 to Ver1.3
  • UNIVERGE IX-R/IX-V series Ver1.4.21 to Ver1.4.28
  • UNIVERGE IX-R/IX-V series Ver1.5.23

As for the details of affected product names and versions, refer to the information provided by the developer.
Impact

If a remote unauthenticated attacker sends a specially crafted message to the WebGUI of the affected product, an arbitrary command may be executed without authentication.
Solution

[Update the software]
Apply the appropriate update according to the information provided by the developer.

[Apply the workaround]
Disable the affected product's WebGUI if the update cannot be applied.

For more details, refer to the information provided by the developer.
Vendor Information

NEC Corporation
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-16876
References

  1. JVN : JVN#81414813
Revision History

  • [2026/08/21]
      Web page was published