CVE-2026-16876
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.
| CWE | CWE-306 |
| Vendor | nec corporation |
| Product | univerge ix-r/ix-v |
| Published | Sep 7, 2026 |
| Last Updated | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for nec corporation univerge ix-r/ix-v
Be the first to know when new unknown vulnerabilities affecting nec corporation univerge ix-r/ix-v are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
NEC Corporation / UNIVERGE IX-R/IX-V
All versions from Ver1.1 through Ver1.3, All versions from Ver1.4.21 through Ver1.4.28 and Ver1.5.23
References
Credits
๐ Kojiro Enokida of Sophos Ltd.