Japan
サイト内の現在位置
Authentication Bypass Vulnerability in the WebGUI of Series UNIVERGE IX-R/IX-V
Number: NV26-005
CVE: CVE-2026-16876
Overview
An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V.
A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device.
Products Affected
UNIVERGE IX-R/IX-V
Affected Version
All versions from Ver1.1 through Ver1.3
All versions from Ver1.4.21 through Ver1.4.28
Ver1.5.23
Solution
Please apply one of the following measures:
1.Update to the latest version
https://jpn.nec.com/univerge/ix-nrv/Support/Security-Info/NV26-005.html
2.Disable the WebGUI
no http-server ip enable
References
CVE-2026-16876
https://www.cve.org/CVERecord?id=CVE-2026-16876
Credit
reported by Sophos Ltd. Mr. Kojiro Enokida.
Update
- 2026/08/21
-
First edition