CVE-2026-16876
nicheAuthentication Bypass in NEC UNIVERGE IX-R/IX-V Router WebGUI
NEC's UNIVERGE IX-R and IX-V series routers contain a missing-authentication flaw (CWE-306) in their WebGUI that allows a user to bypass login entirely. An attacker triggers it by tampering with WebGUI messages and sending the crafted requests to the device's web interface over the network. Successful exploitation grants the ability to execute arbitrary CLI commands on the router, giving full control over device configuration and traffic (CVSS 4.0 rates the impact as critical, 9.3). Any organization running an IX-R or IX-V router whose WebGUI is reachable from the internet is exposed; units whose web interface is restricted to internal management networks face substantially lower risk. There is no known exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV catalog, with EPSS estimating only a 0.3% chance of exploitation in the next 30 days.
What to do: Check the NEC PSIRT advisory for CVE-2026-16876 to identify affected firmware revisions and apply the fixed firmware when released. Until then, restrict access to the router's WebGUI to trusted management networks or via ACLs/firewall rules, and confirm no internet-facing WebGUI listeners remain on IX-R/IX-V units. Review device logs for unexpected configuration changes or unrecognized CLI commands that may indicate tampering.
| NEC UNIVERGE IX-R series routers (WebGUI) | — |
| NEC UNIVERGE IX-V series routers (WebGUI) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.
- Weakness
- CWE-306
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.