サイト内の現在位置

Authentication Bypass Vulnerability in the WebGUI of Series UNIVERGE IX-R/IX-V

Number: NV26-005
CVE: CVE-2026-16876

Overview

An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V.
A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device.

Products Affected

UNIVERGE IX-R/IX-V

Affected Version

All versions from Ver1.1 through Ver1.3
All versions from Ver1.4.21 through Ver1.4.28
Ver1.5.23

Solution

Please apply one of the following measures:
 1.Update to the latest version
https://jpn.nec.com/univerge/ix-nrv/Support/Security-Info/NV26-005.html
 2.Disable the WebGUI
     no http-server ip enable

References

Credit

reported by Sophos Ltd. Mr. Kojiro Enokida.

Update

2026/08/21
First edition