Search

Find a vulnerability

Search criteria

    145 vulnerabilities by NEC Corporation

    CVE-2026-16876 (GCVE-0-2026-16876)

    Vulnerability from cvelistv5 – Published: 2026-09-07 00:48 – Updated: 2026-09-08 15:32
    VLAI
    Summary
    An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-08 15:32 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Impacted products
    Vendor Product Version
    NEC Corporation UNIVERGE IX-R/IX-V Affected: All versions from Ver1.1 through Ver1.3, All versions from Ver1.4.21 through Ver1.4.28 and Ver1.5.23
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-16876",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-08T15:32:24.111712Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-08T15:32:48.460Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX-R/IX-V",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions from Ver1.1 through Ver1.3, All versions from Ver1.4.21 through Ver1.4.28 and Ver1.5.23"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Kojiro Enokida of Sophos Ltd."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet."
                }
              ],
              "value": "An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306: Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-07T00:48:01.015Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv26-005_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2026-16876",
        "datePublished": "2026-09-07T00:48:01.015Z",
        "dateReserved": "2026-07-24T04:35:25.244Z",
        "dateUpdated": "2026-09-08T15:32:48.460Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-8797 (GCVE-0-2026-8797)

    Vulnerability from cvelistv5 – Published: 2026-06-26 04:14 – Updated: 2026-06-26 12:19
    VLAI
    Summary
    An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-26 12:19 UTC
    CWE
    • CWE-782 - Exposed IOCTL with Insufficient Access Control
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-8797",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-26T12:19:40.756620Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-26T12:19:51.182Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "ExpressUpdate Agent for Windows",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.24 and prior"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "MASAHIRO IIDA of LAC Co., Ltd."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges."
                }
              ],
              "value": "An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with SYSTEM privileges."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-782",
                  "description": "CWE-782: Exposed IOCTL with Insufficient Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-26T04:19:19.204Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv26-004_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2026-8797",
        "datePublished": "2026-06-26T04:14:19.370Z",
        "dateReserved": "2026-05-18T01:11:09.851Z",
        "dateUpdated": "2026-06-26T12:19:51.182Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-12852 (GCVE-0-2025-12852)

    Vulnerability from cvelistv5 – Published: 2025-11-19 01:01 – Updated: 2025-11-19 17:13
    VLAI
    Summary
    DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC environment to cause unintended operations on the user's device.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-11-19 17:13 UTC
    CWE
    • CWE-427 - Uncontrolled Search Path Element
    Impacted products
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-12852",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-11-19T17:13:04.376581Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-11-19T17:13:10.642Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "RakurakuMusen Start EX",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "All versions"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Kohei Kuroda"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC environment to cause unintended operations on the user\u0027s device."
                }
              ],
              "value": "DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC environment to cause unintended operations on the user\u0027s device."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.4,
                "baseSeverity": "HIGH",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-427",
                  "description": "CWE-427: Uncontrolled Search Path Element",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-19T01:01:46.374Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv25-007_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2025-12852",
        "datePublished": "2025-11-19T01:01:46.374Z",
        "dateReserved": "2025-11-07T04:30:21.085Z",
        "dateUpdated": "2025-11-19T17:13:10.642Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-11546 (GCVE-0-2025-11546)

    Vulnerability from cvelistv5 – Published: 2025-11-07 01:09 – Updated: 2025-11-07 18:29
    VLAI
    Summary
    CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, EXPRESSCLUSTER X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 allows an attacker sends specially crafted network packets to the product, arbitrary OS commands may be executed without authentication.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-11-07 18:29 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-11546",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-11-07T18:29:04.715150Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-11-07T18:29:57.236Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "CLUSTERPRO X for Linux (EXPRESSCLUSTER X for Linux)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.0, 4.1, 4.2, 5.0, 5.1 and 5.2"
                }
              ]
            },
            {
              "product": "CLUSTERPRO X SingleServerSafe for Linux (EXPRESSCLUSTER X SingleServerSafe for Linux)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "4.0, 4.1, 4.2, 5.0, 5.1 and 5.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, EXPRESSCLUSTER X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 allows an attacker sends specially crafted network packets to the product, arbitrary OS commands may be executed without authentication."
                }
              ],
              "value": "CLUSTERPRO X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 and EXPRESSCLUSTER X for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, CLUSTERPRO X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2, EXPRESSCLUSTER X SingleServerSafe for Linux 4.0, 4.1, 4.2, 5.0, 5.1 and 5.2 allows an attacker sends specially crafted network packets to the product, arbitrary OS commands may be executed without authentication."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 9.3,
                "baseSeverity": "CRITICAL",
                "exploitMaturity": "NOT_DEFINED",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-11-07T04:04:50.054Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv25-006_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2025-11546",
        "datePublished": "2025-11-07T01:09:08.662Z",
        "dateReserved": "2025-10-09T06:48:19.068Z",
        "dateUpdated": "2025-11-07T18:29:57.236Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-8153 (GCVE-0-2025-8153)

    Vulnerability from cvelistv5 – Published: 2025-09-17 02:10 – Updated: 2025-09-17 13:45
    VLAI
    Summary
    Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8.36, from Ver.10.9.11 to Ver.10.9.24, from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6 and UNIVERGE IX-R/IX-V Ver1.3.16, Ver1.3.21 allows a attacker to inject an arbitrary scripts may be executed on the user's browser.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-09-17 13:44 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Impacted products
    Vendor Product Version
    NEC Corporation UNIVERGE IX Affected: from Ver.9.5 to Ver.10.7
    Create a notification for this product.
    NEC Corporation UNIVERGE IX Affected: from Ver.10.8.21 to Ver.10.8.36
    Create a notification for this product.
    NEC Corporation UNIVERGE IX Affected: from Ver.10.9.11 to Ver.10.9.24
    Create a notification for this product.
    NEC Corporation UNIVERGE IX Affected: from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6
    Create a notification for this product.
    NEC Corporation UNIVERGE IX-R/IX-V Affected: Ver1.3.16, Ver1.3.21
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-8153",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-09-17T13:44:45.472287Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-09-17T13:45:14.075Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "from Ver.9.5 to Ver.10.7"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "from Ver.10.8.21 to Ver.10.8.36"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "from Ver.10.9.11 to Ver.10.9.24"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX-R/IX-V",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver1.3.16, Ver1.3.21"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "RyotaK of GMO Flatt Security Inc."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8.36, from Ver.10.9.11 to Ver.10.9.24, from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6 and UNIVERGE IX-R/IX-V Ver1.3.16, Ver1.3.21 allows a attacker to inject an arbitrary scripts may be executed on the user\u0027s browser."
                }
              ],
              "value": "Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8.36, from Ver.10.9.11 to Ver.10.9.24, from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6 and UNIVERGE IX-R/IX-V Ver1.3.16, Ver1.3.21 allows a attacker to inject an arbitrary scripts may be executed on the user\u0027s browser."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "LOW",
                "subIntegrityImpact": "LOW",
                "userInteraction": "ACTIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-09-17T02:10:50.272Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv25-005_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2025-8153",
        "datePublished": "2025-09-17T02:10:09.645Z",
        "dateReserved": "2025-07-25T01:38:55.766Z",
        "dateUpdated": "2025-09-17T13:45:14.075Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-6466 (GCVE-0-2024-6466)

    Vulnerability from cvelistv5 – Published: 2025-01-21 10:03 – Updated: 2025-01-21 19:43
    VLAI
    Summary
    NEC Corporation's WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FRAME-OPTIONS is not specified.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-21 19:20 UTC
    CWE
    • CWE-1021 - Improper Restriction of Rendered UI Layers or Frames
    Impacted products
    Vendor Product Version
    NEC Corporation WebSAM DeploymentManager Affected: from v6.0 to v6.80
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6466",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-21T19:20:47.843701Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-21T19:43:54.175Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "WebSAM DeploymentManager",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "from v6.0 to v6.80"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "NEC Corporation\u0027s WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FRAME-OPTIONS is not specified."
                }
              ],
              "value": "NEC Corporation\u0027s WebSAM DeploymentManager v6.0 to v6.80 allows an attacker to reset configurations or restart products via network with X-FRAME-OPTIONS is not specified."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-1021",
                  "description": "CWE-1021: Improper Restriction of Rendered UI Layers or Frames",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-21T10:03:24.544Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv15-019_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2024-6466",
        "datePublished": "2025-01-21T10:03:24.544Z",
        "dateReserved": "2024-07-03T00:18:49.513Z",
        "dateUpdated": "2025-01-21T19:43:54.175Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-0356 (GCVE-0-2025-0356)

    Vulnerability from cvelistv5 – Published: 2025-01-15 07:24 – Updated: 2025-04-03 15:36
    VLAI
    Summary
    NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands via the network.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-03 15:36 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    NEC Corporation WX1500HP Affected: Ver.1.4.2 and earlier
    Create a notification for this product.
    NEC Corporation WX3600HP Affected: Ver.1.5.3 and earlier
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-0356",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-03T15:36:52.964723Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-03T15:36:59.555Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "WX1500HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.4.2 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WX3600HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.5.3 and earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Kakeru Kajihara of NTT Security Holdings."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands via the network."
                }
              ],
              "value": "NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands via the network."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-17T10:02:45.212Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv25-003_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2025-0356",
        "datePublished": "2025-01-15T07:24:25.831Z",
        "dateReserved": "2025-01-09T06:20:51.166Z",
        "dateUpdated": "2025-04-03T15:36:59.555Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-0355 (GCVE-0-2025-0355)

    Vulnerability from cvelistv5 – Published: 2025-01-15 07:23 – Updated: 2025-01-21 03:34
    VLAI
    Summary
    Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.0 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to get a Wi-Fi password via the network.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-01-15 15:01 UTC
    CWE
    • CWE-306 - Missing Authentication for Critical Function
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-0355",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-01-15T15:01:29.278695Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-01-15T15:01:48.659Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "WG2600HS",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.7.2 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF1200CR",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.6.0 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200CR",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.5.0 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "GB1200PE",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.3.0 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG2600HP4",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.4.2 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG2600HM4",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.4.2 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG2600HS2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.3.2 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WX3000HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.2.4.2 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WX4200D5",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.2.4 and earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Takayuki Sasaki and Katsunari Yoshioka of Yokohama National University."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.0 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to get a Wi-Fi password via the network."
                }
              ],
              "value": "Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.0 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to get a Wi-Fi password via the network."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 7.5,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-306",
                  "description": "CWE-306: Missing Authentication for Critical Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-21T03:34:13.440Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv25-003_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2025-0355",
        "datePublished": "2025-01-15T07:23:39.481Z",
        "dateReserved": "2025-01-09T06:20:49.647Z",
        "dateUpdated": "2025-01-21T03:34:13.440Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2025-0354 (GCVE-0-2025-0354)

    Vulnerability from cvelistv5 – Published: 2025-01-15 07:21 – Updated: 2025-04-03 15:38
    VLAI
    Summary
    Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to inject an arbitrary script via the network.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-04-03 15:37 UTC
    CWE
    • CWE-79 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-0354",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-04-03T15:37:52.480740Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-04-03T15:38:02.872Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "WG2600HS",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.7.2 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG2600HP4",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.4.2 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG2600HM4",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.4.2 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG2600HS2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.3.2 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WX3000HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.2.4.2 and earlier"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WX4200D5",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver.1.2.4 and earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Takayuki Sasaki and Katsunari Yoshioka of Yokohama National University."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to inject an arbitrary script via the network."
                }
              ],
              "value": "Cross-site scripting vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier, WG2600HS2 Ver.1.3.2 and earlier, WX3000HP Ver.2.4.2 and earlier and WX4200D5 Ver.1.2.4 and earlier allows a attacker to inject an arbitrary script via the network."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.8,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "HIGH",
                "scope": "CHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-79",
                  "description": "CWE-79: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-02-17T10:02:08.927Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv25-003_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2025-0354",
        "datePublished": "2025-01-15T07:21:41.810Z",
        "dateReserved": "2025-01-09T06:20:47.803Z",
        "dateUpdated": "2025-04-03T15:38:02.872Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-11014 (GCVE-0-2024-11014)

    Vulnerability from cvelistv5 – Published: 2024-11-29 08:06 – Updated: 2025-07-24 14:37
    VLAI
    Summary
    Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the management interface.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-29 13:33 UTC
    CWE
    • CWE-352 - Cross-Site Request Forgery (CSRF)
    Impacted products
    Vendor Product Version
    NEC Corporation UNIVERGE IX Affected: from Ver9.2 to Ver10.10.21
    Create a notification for this product.
    NEC Corporation UNIVERGE IX Affected: for Ver10.8 up to Ver10.8.27
    Create a notification for this product.
    NEC Corporation UNIVERGE IX Affected: for Ver10.9 up to Ver10.9.14
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-11014",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-29T13:33:02.584725Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-07-24T14:37:20.170Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "from Ver9.2 to Ver10.10.21"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "for Ver10.8 up to Ver10.8.27"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "for Ver10.9 up to Ver10.9.14"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "RyotaK of Flatt Security Inc."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the management interface."
                }
              ],
              "value": "Cross-site request forgery (CSRF) vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27 and for Ver10.9 up to Ver10.9.14 allows a attacker to hijack the authentication of screens on the device via the management interface."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 4.3,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "NONE",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-352",
                  "description": "CWE-352: Cross-Site Request Forgery (CSRF)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-07-23T07:22:49.583Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv24-009_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2024-11014",
        "datePublished": "2024-11-29T08:06:19.712Z",
        "dateReserved": "2024-11-08T02:59:57.594Z",
        "dateUpdated": "2025-07-24T14:37:20.170Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-11013 (GCVE-0-2024-11013)

    Vulnerability from cvelistv5 – Published: 2024-11-29 08:03 – Updated: 2025-07-24 14:40
    VLAI
    Summary
    Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-29 13:34 UTC
    CWE
    • CWE-77 - Improper Neutralization of Special Elements used in a Command ('Command Injection')
    Impacted products
    Vendor Product Version
    NEC Corporation UNIVERGE IX Affected: from Ver9.2 to Ver10.10.21
    Create a notification for this product.
    NEC Corporation UNIVERGE IX Affected: for Ver10.8 up to Ver10.8.27
    Create a notification for this product.
    NEC Corporation UNIVERGE IX Affected: for Ver10.9 up to Ver10.9.14
    Create a notification for this product.
    NEC Corporation UNIVERGE IX-R/IX-V Affected: Ver1.2.15 and earlier
    Create a notification for this product.
    nec univerge_ix Affected: 9.2 , ≤ 10.10.21 (custom)
    Affected: 10.8 , ≤ 10.8.27 (custom)
    Affected: 10.9 , ≤ 10.9.14 (custom)
        cpe:2.3:a:nec:univerge_ix:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nec:univerge_ix:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "univerge_ix",
                "vendor": "nec",
                "versions": [
                  {
                    "lessThanOrEqual": "10.10.21",
                    "status": "affected",
                    "version": "9.2",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "10.8.27",
                    "status": "affected",
                    "version": "10.8",
                    "versionType": "custom"
                  },
                  {
                    "lessThanOrEqual": "10.9.14",
                    "status": "affected",
                    "version": "10.9",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-11013",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-29T13:34:19.048337Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2025-07-24T14:40:37.401Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "from Ver9.2 to Ver10.10.21"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "for Ver10.8 up to Ver10.8.27"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "for Ver10.9 up to Ver10.9.14"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "UNIVERGE IX-R/IX-V",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "Ver1.2.15 and earlier"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "RyotaK of Flatt Security Inc."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface."
                }
              ],
              "value": "Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device via the management interface."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 7.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "HIGH",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-77",
                  "description": "CWE-77: Improper Neutralization of Special Elements used in a Command (\u0027Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-07-23T07:21:57.134Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv24-009_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2024-11013",
        "datePublished": "2024-11-29T08:03:07.458Z",
        "dateReserved": "2024-11-08T02:59:55.534Z",
        "dateUpdated": "2025-07-24T14:40:37.401Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-40895 (GCVE-0-2024-40895)

    Vulnerability from cvelistv5 – Published: 2024-07-30 08:37 – Updated: 2024-08-02 04:39
    VLAI
    Summary
    FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker to execute arbitrary OS commands when certain conditions are met in an environment where the notification program setting is enabled and the executable file path is set to a batch file (.bat) or command file (.cmd) extension.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-07-30 14:16 UTC
    CWE
    • OS command injection
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    FFRI Security, Inc. FFRI AMC Affected: 3.4.0 to 3.5.3
    Create a notification for this product.
    NEC Corporation FFRI AMC for ActSecure χ Affected: 3.4.0 to 3.5.3
    Create a notification for this product.
    Sky Co., Ltd. EDR Plus Pack Affected: Bundled FFRI AMC versions 3.4.0 to 3.5.3
    Create a notification for this product.
    ffri ffri_amc Affected: 3.4.0 , < 3.5.3 (custom)
        cpe:2.3:a:ffri:ffri_amc:3.4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    skygroup edr_plus_pack Affected: 3.4.0 , < 3.5.3 (custom)
        cpe:2.3:a:skygroup:edr_plus_pack:3.4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    skygroup edr_plus_pack_cloud Affected: 3.4.0 , < 3.5.3 (custom)
        cpe:2.3:a:skygroup:edr_plus_pack_cloud:3.4.0:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:ffri:ffri_amc:3.4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "ffri_amc",
                "vendor": "ffri",
                "versions": [
                  {
                    "lessThan": "3.5.3",
                    "status": "affected",
                    "version": "3.4.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:skygroup:edr_plus_pack:3.4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "edr_plus_pack",
                "vendor": "skygroup",
                "versions": [
                  {
                    "lessThan": "3.5.3",
                    "status": "affected",
                    "version": "3.4.0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:skygroup:edr_plus_pack_cloud:3.4.0:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "edr_plus_pack_cloud",
                "vendor": "skygroup",
                "versions": [
                  {
                    "lessThan": "3.5.3",
                    "status": "affected",
                    "version": "3.4.0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "HIGH",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 6.4,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "LOW",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "REQUIRED",
                  "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-40895",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-07-30T14:16:27.684515Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-78",
                    "description": "CWE-78 Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-31T17:31:56.655Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T04:39:55.373Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.ffri.jp/assets/files/other_docs/20240729.pdf"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.support.nec.co.jp/View.aspx?id=3140109694"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://www.skyseaclientview.net/news/240729_01/"
              },
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://jvn.jp/en/jp/JVN26734798/"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "FFRI AMC",
              "vendor": "FFRI Security, Inc.",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.4.0 to 3.5.3"
                }
              ]
            },
            {
              "product": "FFRI AMC for ActSecure \u03c7",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "3.4.0 to 3.5.3"
                }
              ]
            },
            {
              "product": "EDR Plus Pack",
              "vendor": "Sky Co., Ltd.",
              "versions": [
                {
                  "status": "affected",
                  "version": "Bundled FFRI AMC versions 3.4.0 to 3.5.3"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "FFRI AMC versions 3.4.0 to 3.5.3 and some OEM products that implement/bundle FFRI AMC versions 3.4.0 to 3.5.3 allow a remote unauthenticated attacker to execute arbitrary OS commands when certain conditions are met in an environment where the notification program setting is enabled and the executable file path is set to a batch file (.bat) or command file (.cmd) extension."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "description": "OS command injection",
                  "lang": "en",
                  "type": "text"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-07-30T08:37:07.607Z",
            "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
            "shortName": "jpcert"
          },
          "references": [
            {
              "url": "https://www.ffri.jp/assets/files/other_docs/20240729.pdf"
            },
            {
              "url": "https://www.support.nec.co.jp/View.aspx?id=3140109694"
            },
            {
              "url": "https://www.skyseaclientview.net/news/240729_01/"
            },
            {
              "url": "https://jvn.jp/en/jp/JVN26734798/"
            }
          ]
        }
      },
      "cveMetadata": {
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "assignerShortName": "jpcert",
        "cveId": "CVE-2024-40895",
        "datePublished": "2024-07-30T08:37:07.607Z",
        "dateReserved": "2024-07-12T03:00:58.480Z",
        "dateUpdated": "2024-08-02T04:39:55.373Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28013 (GCVE-0-2024-28013)

    Vulnerability from cvelistv5 – Published: 2024-03-28 00:57 – Updated: 2025-01-14 04:02
    VLAI
    Summary
    Use of Insufficiently Random Values vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to change settings via the internet.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-19 19:14 UTC
    CWE
    • CWE-330 - Use of Insufficiently Random Values
    Impacted products
    Vendor Product Version
    NEC Corporation WG1800HP4 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1900HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1900HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation W1200EX(-MS) Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF300HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation W300P Affected: all versions
    Create a notification for this product.
    NEC Corporation WF800HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8165N Affected: all versions
    Create a notification for this product.
    NEC Corporation WG2200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF1200HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WF1200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG600HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG300HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF300HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1400HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8175N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR9300N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8750N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8160N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR9500N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8600N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8370N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8170N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8700N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8300N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8150N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR4100N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR4500N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8100N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8500N Affected: all versions
    Create a notification for this product.
    NEC Corporation CR2500P Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8400N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8200N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR1200H Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7870S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6670S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7850S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6650S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6600H Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7800H Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3400RN Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3450RN Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3500R Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3600R Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3800R Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8166N Affected: all versions
    Create a notification for this product.
    NEC Corporation MR01LN Affected: all versions
    Create a notification for this product.
    NEC Corporation MR02LN Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1810HP(JE) Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1810HP(MF) Affected: all versions
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "NONE",
                  "baseScore": 5.3,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "NONE",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28013",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-19T19:14:52.309865Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-19T19:15:03.453Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:48:47.644Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP4",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1900HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1900HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "W1200EX(-MS)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF300HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "W300P",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF800HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8165N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG2200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF1200HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF1200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG600HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG300HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF300HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1400HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8175N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR9300N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8750N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8160N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR9500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8600N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8370N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8170N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8700N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8300N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8150N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR4100N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR4500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8100N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "CR2500P",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8400N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8200N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR1200H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7870S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6670S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7850S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6650S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6600H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7800H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3400RN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3450RN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3500R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3600R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3800R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8166N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "MR01LN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "MR02LN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1810HP(JE)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1810HP(MF)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Yudai Morii, Takaya Noma, Takayuki Sasaki and Katsunari Yoshioka of Yokohama National University."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Use of Insufficiently Random Values vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to change settings via the internet."
                }
              ],
              "value": "Use of Insufficiently Random Values vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to change settings via the internet."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-330",
                  "description": "CWE-330: Use of Insufficiently Random Values",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-14T04:02:18.281Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv24-001_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2024-28013",
        "datePublished": "2024-03-28T00:57:38.295Z",
        "dateReserved": "2024-02-29T08:40:13.581Z",
        "dateUpdated": "2025-01-14T04:02:18.281Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28014 (GCVE-0-2024-28014)

    Vulnerability from cvelistv5 – Published: 2024-03-28 00:56 – Updated: 2025-01-14 04:05
    VLAI
    Summary
    Stack-based Buffer Overflow vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to execute an arbitrary command via the internet.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-08-23 17:36 UTC
    CWE
    • CWE-121 - Stack-based Buffer Overflow
    Impacted products
    Vendor Product Version
    NEC Corporation WG1800HP4 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1900HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1900HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation W1200EX(-MS) Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF300HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation W300P Affected: all versions
    Create a notification for this product.
    NEC Corporation WF800HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8165N Affected: all versions
    Create a notification for this product.
    NEC Corporation WG2200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF1200HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WF1200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG600HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG300HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF300HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1400HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8175N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR9300N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8750N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8160N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR9500N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8600N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8370N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8170N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8700N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8300N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8150N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR4100N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR4500N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8100N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8500N Affected: all versions
    Create a notification for this product.
    NEC Corporation CR2500P Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8400N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8200N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR1200H Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7870S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6670S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7850S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6650S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6600H Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7800H Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3400RN Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3450RN Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3500R Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3600R Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3800R Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8166N Affected: all versions
    Create a notification for this product.
    NEC Corporation MR01LN Affected: all versions
    Create a notification for this product.
    NEC Corporation MR02LN Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1810HP(JE) Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1810HP(MF) Affected: all versions
    Create a notification for this product.
    nec aterm_w1200ex\(-ms\)_firmware Affected: 0 , ≤ * (custom)
        cpe:2.3:o:nec:aterm_cr2500p_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_mr01ln_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_mr02ln_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_w300p_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wf1200hp2_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wf1200hp_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wf300hp2_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wf300hp_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wf800hp_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1200hp2_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1200hp3_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1200hp_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1200hs2_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1200hs3_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1200hs_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1400hp_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1800hp2_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1800hp3_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1800hp4_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1800hp_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1810hp\(je\)_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1810hp\(mf\)_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1900hp2_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1900hp_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg2200hp_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg300hp_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg600hp_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wm3400rn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wm3450rn_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wm3500r_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wm3600r_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wm3800r_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr1200h_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr4100n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr4500n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr6600h_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr6650s_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr6670s_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr7800h_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr7850s_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr7870s_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8100n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8150n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8160n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8165n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8166n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8170n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8175n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8200n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8300n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8370n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8400n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8500n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8600n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8700n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8750n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr9300n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr9500n_firmware:*:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_w1200ex\(-ms\)_firmware:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:48:47.651Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:nec:aterm_cr2500p_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_mr01ln_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_mr02ln_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_w300p_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wf1200hp2_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wf1200hp_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wf300hp2_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wf300hp_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wf800hp_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1200hp2_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1200hp3_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1200hp_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1200hs2_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1200hs3_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1200hs_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1400hp_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1800hp2_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1800hp3_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1800hp4_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1800hp_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1810hp\\(je\\)_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1810hp\\(mf\\)_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1900hp2_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1900hp_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg2200hp_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg300hp_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg600hp_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wm3400rn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wm3450rn_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wm3500r_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wm3600r_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wm3800r_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr1200h_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr4100n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr4500n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr6600h_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr6650s_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr6670s_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr7800h_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr7850s_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr7870s_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8100n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8150n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8160n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8165n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8166n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8170n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8175n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8200n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8300n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8370n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8400n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8500n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8600n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8700n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8750n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr9300n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr9500n_firmware:*:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_w1200ex\\(-ms\\)_firmware:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "aterm_w1200ex\\(-ms\\)_firmware",
                "vendor": "nec",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28014",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-08-23T17:36:07.288926Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "problemTypes": [
              {
                "descriptions": [
                  {
                    "cweId": "CWE-121",
                    "description": "CWE-121 Stack-based Buffer Overflow",
                    "lang": "en",
                    "type": "CWE"
                  }
                ]
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-23T18:42:34.009Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP4",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1900HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1900HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "W1200EX(-MS)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF300HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "W300P",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF800HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8165N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG2200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF1200HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF1200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG600HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG300HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF300HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1400HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8175N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR9300N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8750N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8160N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR9500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8600N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8370N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8170N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8700N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8300N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8150N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR4100N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR4500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8100N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "CR2500P",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8400N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8200N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR1200H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7870S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6670S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7850S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6650S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6600H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7800H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3400RN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3450RN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3500R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3600R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3800R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8166N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "MR01LN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "MR02LN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1810HP(JE)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1810HP(MF)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Takayuki Sasaki and Katsunari Yoshioka of Yokohama National University."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Stack-based Buffer Overflow vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to execute an arbitrary command via the internet."
                }
              ],
              "value": "Stack-based Buffer Overflow vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to execute an arbitrary command via the internet."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-121",
                  "description": "CWE-121: Stack-based Buffer Overflow",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-14T04:05:52.531Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv24-001_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2024-28014",
        "datePublished": "2024-03-28T00:56:39.075Z",
        "dateReserved": "2024-02-29T08:40:13.582Z",
        "dateUpdated": "2025-01-14T04:05:52.531Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28015 (GCVE-0-2024-28015)

    Vulnerability from cvelistv5 – Published: 2024-03-28 00:56 – Updated: 2025-01-14 04:07
    VLAI
    Summary
    Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to execute an arbitrary OS command with the root privilege via the internet.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-04-02 13:05 UTC
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command
    Impacted products
    Vendor Product Version
    NEC Corporation WG1800HP4 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1900HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1900HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation W1200EX(-MS) Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF300HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation W300P Affected: all versions
    Create a notification for this product.
    NEC Corporation WF800HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8165N Affected: all versions
    Create a notification for this product.
    NEC Corporation WG2200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF1200HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WF1200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG600HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG300HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF300HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1400HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8175N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR9300N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8750N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8160N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR9500N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8600N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8370N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8170N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8700N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8300N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8150N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR4100N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR4500N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8100N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8500N Affected: all versions
    Create a notification for this product.
    NEC Corporation CR2500P Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8400N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8200N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR1200H Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7870S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6670S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7850S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6650S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6600H Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7800H Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3400RN Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3450RN Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3500R Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3600R Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3800R Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8166N Affected: all versions
    Create a notification for this product.
    NEC Corporation MR01LN Affected: all versions
    Create a notification for this product.
    NEC Corporation MR02LN Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1810HP(JE) Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1810HP(MF) Affected: all versions
    Create a notification for this product.
    nec aterm_wg1800hp4_firmware Affected: 0 , ≤ * (custom)
        cpe:2.3:o:nec:aterm_wr8700n_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_w1200ex-ms_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wf300hp2_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wf300hp_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wf800hp_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1200hp_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1200hs2_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1200hs_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1400hp_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1800hp2_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:h:nec:aterm_wg1800hp3:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1800hp_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1900hp_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg2200hp_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg300hp_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg600hp_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8165n_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8170n_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8175n_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8370n_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8600n_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr8750n_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr9300n_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wr9500n_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1200hp3_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1900hp2_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1200hs3_firmware:-:*:*:*:*:*:*:*
        cpe:2.3:o:nec:aterm_wg1800hp4_firmware:-:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:o:nec:aterm_wr8700n_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_w1200ex-ms_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wf300hp2_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wf300hp_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wf800hp_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1200hp_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1200hs2_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1200hs_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1400hp_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1800hp2_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:h:nec:aterm_wg1800hp3:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1800hp_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1900hp_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg2200hp_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg300hp_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg600hp_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8165n_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8170n_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8175n_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8370n_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8600n_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr8750n_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr9300n_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wr9500n_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1200hp3_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1900hp2_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1200hs3_firmware:-:*:*:*:*:*:*:*",
                  "cpe:2.3:o:nec:aterm_wg1800hp4_firmware:-:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "aterm_wg1800hp4_firmware",
                "vendor": "nec",
                "versions": [
                  {
                    "lessThanOrEqual": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28015",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-04-02T13:05:24.151876Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-07-29T16:41:58.912Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:48:48.238Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP4",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1900HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1900HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "W1200EX(-MS)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF300HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "W300P",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF800HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8165N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG2200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF1200HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF1200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG600HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG300HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF300HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1400HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8175N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR9300N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8750N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8160N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR9500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8600N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8370N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8170N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8700N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8300N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8150N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR4100N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR4500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8100N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "CR2500P",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8400N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8200N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR1200H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7870S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6670S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7850S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6650S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6600H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7800H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3400RN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3450RN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3500R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3600R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3800R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8166N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "MR01LN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "MR02LN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1810HP(JE)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1810HP(MF)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Takayuki Sasaki and Katsunari Yoshioka of Yokohama National University."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to execute an arbitrary OS command with the root privilege via the internet."
                }
              ],
              "value": "Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to execute an arbitrary OS command with the root privilege via the internet."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-14T04:07:45.168Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv24-001_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2024-28015",
        "datePublished": "2024-03-28T00:56:20.758Z",
        "dateReserved": "2024-02-29T08:40:36.326Z",
        "dateUpdated": "2025-01-14T04:07:45.168Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28016 (GCVE-0-2024-28016)

    Vulnerability from cvelistv5 – Published: 2024-03-28 00:55 – Updated: 2025-01-14 04:14
    VLAI
    Summary
    Improper Access Controlvulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to get device informations via the internet.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-28 18:37 UTC
    CWE
    • CWE-284 - Improper Access Control
    Impacted products
    Vendor Product Version
    NEC Corporation WG1800HP4 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1900HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1900HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation W1200EX(-MS) Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF300HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation W300P Affected: all versions
    Create a notification for this product.
    NEC Corporation WF800HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8165N Affected: all versions
    Create a notification for this product.
    NEC Corporation WG2200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF1200HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WF1200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG600HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG300HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF300HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1400HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8175N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR9300N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8750N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8160N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR9500N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8600N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8370N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8170N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8700N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8300N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8150N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR4100N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR4500N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8100N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8500N Affected: all versions
    Create a notification for this product.
    NEC Corporation CR2500P Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8400N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8200N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR1200H Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7870S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6670S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7850S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6650S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6600H Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7800H Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3400RN Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3450RN Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3500R Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3600R Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3800R Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8166N Affected: all versions
    Create a notification for this product.
    NEC Corporation MR01LN Affected: all versions
    Create a notification for this product.
    NEC Corporation MR02LN Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1810HP(JE) Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1810HP(MF) Affected: all versions
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "LOW",
                  "baseScore": 6,
                  "baseSeverity": "MEDIUM",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "LOW",
                  "privilegesRequired": "HIGH",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28016",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-28T18:37:34.619893Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-12-06T21:09:12.605Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          },
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:48:47.645Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP4",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1900HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1900HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "W1200EX(-MS)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF300HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "W300P",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF800HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8165N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG2200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF1200HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF1200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG600HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG300HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF300HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1400HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8175N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR9300N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8750N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8160N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR9500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8600N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8370N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8170N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8700N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8300N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8150N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR4100N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR4500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8100N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "CR2500P",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8400N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8200N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR1200H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7870S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6670S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7850S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6650S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6600H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7800H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3400RN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3450RN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3500R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3600R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3800R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8166N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "MR01LN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "MR02LN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1810HP(JE)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1810HP(MF)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Takayuki Sasaki and Katsunari Yoshioka of Yokohama National University."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper Access Controlvulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to get device informations via the internet."
                }
              ],
              "value": "Improper Access Controlvulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to get device informations via the internet."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284: Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-14T04:14:44.988Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv24-001_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2024-28016",
        "datePublished": "2024-03-28T00:55:50.880Z",
        "dateReserved": "2024-02-29T08:40:36.327Z",
        "dateUpdated": "2025-01-14T04:14:44.988Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-28012 (GCVE-0-2024-28012)

    Vulnerability from cvelistv5 – Published: 2024-03-28 00:55 – Updated: 2025-01-14 03:59
    VLAI
    Summary
    Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to execute an arbitrary command with the root privilege via the internet.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-03-28 18:36 UTC
    CWE
    • CWE-287 - Improper Authentication
    Impacted products
    Vendor Product Version
    NEC Corporation WG1800HP4 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1900HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP3 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1900HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation W1200EX(-MS) Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HS Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF300HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation W300P Affected: all versions
    Create a notification for this product.
    NEC Corporation WF800HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8165N Affected: all versions
    Create a notification for this product.
    NEC Corporation WG2200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF1200HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP2 Affected: all versions
    Create a notification for this product.
    NEC Corporation WF1200HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG600HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG300HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WF300HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1800HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1400HP Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8175N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR9300N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8750N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8160N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR9500N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8600N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8370N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8170N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8700N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8300N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8150N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR4100N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR4500N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8100N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8500N Affected: all versions
    Create a notification for this product.
    NEC Corporation CR2500P Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8400N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8200N Affected: all versions
    Create a notification for this product.
    NEC Corporation WR1200H Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7870S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6670S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7850S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6650S Affected: all versions
    Create a notification for this product.
    NEC Corporation WR6600H Affected: all versions
    Create a notification for this product.
    NEC Corporation WR7800H Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3400RN Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3450RN Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3500R Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3600R Affected: all versions
    Create a notification for this product.
    NEC Corporation WM3800R Affected: all versions
    Create a notification for this product.
    NEC Corporation WR8166N Affected: all versions
    Create a notification for this product.
    NEC Corporation MR01LN Affected: all versions
    Create a notification for this product.
    NEC Corporation MR02LN Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1810HP(JE) Affected: all versions
    Create a notification for this product.
    NEC Corporation WG1810HP(MF) Affected: all versions
    Create a notification for this product.
    nec_corporation wg1200hp3 Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1200hp3:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1800hp4 Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1800hp4:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1200hs3 Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1200hs3:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1900hp2 Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1900hp2:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1800hp3 Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1800hp3:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1200hs2 Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1200hs2:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1900hp Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1900hp:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1200hp2 Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1200hp2:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation w1200ex\/ms\/ Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:w1200ex\/ms\/:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1200hs Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1200hs:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1200hp Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1200hp:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wf300hp2 Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wf300hp2:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation w300p Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:w300p:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wf800hp Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wf800hp:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8165n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8165n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg2200hp Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg2200hp:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wf1200hp2 Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wf1200hp2:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1800hp2 Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1800hp2:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wf1200hp Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wf1200hp:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg600hp Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg600hp:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg300hp Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg300hp:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1800hp Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1800hp:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1400hp Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1400hp:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8175n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8175n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr9300n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr9300n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8750n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8750n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8160n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8160n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr9500n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr9500n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8600n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8600n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8370n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8370n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8170n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8170n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8700n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8700n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8300n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8300n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8150n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8150n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr4100n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr4100n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr4500n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr4500n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8100n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8100n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8500n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8500n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation cr2500p Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:cr2500p:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8400n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8400n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8200n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8200n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr1200h Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr1200h:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr7870s Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr7870s:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr6670s Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr6670s:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr7850s Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr7850s:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr6650s Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr6650s:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wm3800r Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wm3800r:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr6600h Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr6600h:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr7800h Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr7800h:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wm3400rn Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wm3400rn:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wm3450rn Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wm3450rn:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wm3500r Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wm3500r:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wm3600r Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wm3600r:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wr8166n Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wr8166n:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation mr01ln Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:mr01ln:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation mr02ln Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:mr02ln:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1810hp\/je\/ Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1810hp\/je\/:*:*:*:*:*:*:*:*
    Create a notification for this product.
    nec_corporation wg1810hp\/mf\/ Affected: 0 , < * (custom)
        cpe:2.3:a:nec_corporation:wg1810hp\/mf\/:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-02T00:48:47.691Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_transferred"
                ],
                "url": "https://https://jpn.nec.com/security-info/secinfo/nv24-001_en.html"
              }
            ],
            "title": "CVE Program Container"
          },
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1200hp3:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1200hp3",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1800hp4:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1800hp4",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1200hs3:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1200hs3",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1900hp2:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1900hp2",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1800hp3:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1800hp3",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1200hs2:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1200hs2",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1900hp:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1900hp",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1200hp2:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1200hp2",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:w1200ex\\/ms\\/:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "w1200ex\\/ms\\/",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1200hs:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1200hs",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1200hp:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1200hp",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wf300hp2:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wf300hp2",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:w300p:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "w300p",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wf800hp:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wf800hp",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8165n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8165n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg2200hp:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg2200hp",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wf1200hp2:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wf1200hp2",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1800hp2:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1800hp2",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wf1200hp:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wf1200hp",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg600hp:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg600hp",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg300hp:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg300hp",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1800hp:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1800hp",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1400hp:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1400hp",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8175n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8175n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr9300n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr9300n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8750n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8750n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8160n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8160n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr9500n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr9500n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8600n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8600n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8370n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8370n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8170n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8170n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8700n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8700n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8300n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8300n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8150n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8150n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr4100n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr4100n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr4500n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr4500n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8100n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8100n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8500n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8500n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:cr2500p:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "cr2500p",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8400n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8400n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8200n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8200n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr1200h:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr1200h",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr7870s:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr7870s",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr6670s:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr6670s",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr7850s:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr7850s",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr6650s:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr6650s",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wm3800r:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wm3800r",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr6600h:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr6600h",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr7800h:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr7800h",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wm3400rn:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wm3400rn",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wm3450rn:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wm3450rn",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wm3500r:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wm3500r",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wm3600r:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wm3600r",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wr8166n:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wr8166n",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:mr01ln:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mr01ln",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:mr02ln:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "mr02ln",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1810hp\\/je\\/:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1810hp\\/je\\/",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              },
              {
                "cpes": [
                  "cpe:2.3:a:nec_corporation:wg1810hp\\/mf\\/:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unknown",
                "product": "wg1810hp\\/mf\\/",
                "vendor": "nec_corporation",
                "versions": [
                  {
                    "lessThan": "*",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "cvssV3_1": {
                  "attackComplexity": "LOW",
                  "attackVector": "NETWORK",
                  "availabilityImpact": "HIGH",
                  "baseScore": 9.8,
                  "baseSeverity": "CRITICAL",
                  "confidentialityImpact": "HIGH",
                  "integrityImpact": "HIGH",
                  "privilegesRequired": "NONE",
                  "scope": "UNCHANGED",
                  "userInteraction": "NONE",
                  "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                  "version": "3.1"
                }
              },
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-28012",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-03-28T18:36:14.164270Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-08-27T19:27:27.700Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP4",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1900HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP3",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1900HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "W1200EX(-MS)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HS",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF300HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "W300P",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF800HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8165N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG2200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF1200HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP2",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF1200HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG600HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG300HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WF300HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1800HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1400HP",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8175N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR9300N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8750N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8160N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR9500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8600N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8370N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8170N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8700N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8300N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8150N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR4100N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR4500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8100N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8500N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "CR2500P",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8400N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8200N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR1200H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7870S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6670S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7850S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6650S",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR6600H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR7800H",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3400RN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3450RN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3500R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3600R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WM3800R",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WR8166N",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "MR01LN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "MR02LN",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1810HP(JE)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            },
            {
              "defaultStatus": "unknown",
              "product": "WG1810HP(MF)",
              "vendor": "NEC Corporation",
              "versions": [
                {
                  "status": "affected",
                  "version": "all versions"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "user": "00000000-0000-4000-9000-000000000000",
              "value": "Katsuhiko Sato and Ryo Kashiro of 00One, Inc."
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to execute an arbitrary command with the root privilege via the internet."
                }
              ],
              "value": "Improper authentication vulnerability in NEC Corporation Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker to execute an arbitrary command with the root privilege via the internet."
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-287",
                  "description": "CWE-287: Improper Authentication",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-01-14T03:59:31.550Z",
            "orgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
            "shortName": "NEC"
          },
          "references": [
            {
              "url": "https://jpn.nec.com/security-info/secinfo/nv24-001_en.html"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "x_generator": {
            "engine": "Vulnogram 0.1.0-dev"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "f2760a35-e0d8-4637-ac4c-cc1a2de3e282",
        "assignerShortName": "NEC",
        "cveId": "CVE-2024-28012",
        "datePublished": "2024-03-28T00:55:05.166Z",
        "dateReserved": "2024-02-29T08:40:13.581Z",
        "dateUpdated": "2025-01-14T03:59:31.550Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    JVNDB-2026-000119

    Vulnerability from jvndb - Published: 2026-08-21 06:39 - Updated:2026-08-21 06:39
    Severity
    Summary
    UNIVERGE IX-R/IX-V series routers vulnerable to missing authentication for critical function
    Details
    UNIVERGE IX-R/IX-V series routers provided by NEC Corporation contain the following vulnerability.
    • Missing authentication for critical function (CWE-306) - CVE-2026-16876
    Kojiro Enokida of SOPHOS reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000119.html",
      "dc:date": "2026-08-21T15:39+09:00",
      "dcterms:issued": "2026-08-21T15:39+09:00",
      "dcterms:modified": "2026-08-21T15:39+09:00",
      "description": "UNIVERGE IX-R/IX-V series routers provided by NEC Corporation contain the following vulnerability.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/306.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://www.cve.org/CVERecord?id=CVE-2026-16876\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eMissing authentication for critical function (CWE-306) - CVE-2026-16876\u003c/li\u003e\u003c/ul\u003eKojiro Enokida of SOPHOS reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000119.html",
      "sec:cpe": {
        "#text": "cpe:/o:nec:univerge",
        "@product": "UNIVERGE",
        "@vendor": "NEC Corporation",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "9.4",
        "@severity": "Critical",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2026-000119",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN81414813/index.html",
          "@id": "JVN#81414813",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-16876",
          "@id": "CVE-2026-16876",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "UNIVERGE IX-R/IX-V series routers vulnerable to missing authentication for critical function"
    }

    JVNDB-2026-000088

    Vulnerability from jvndb - Published: 2026-06-26 05:25 - Updated:2026-06-26 05:25
    Severity
    Summary
    ExpressUpdate Agent for Windows improper access restriction on its named pipe
    Details
    ExpressUpdate Agent for Windows provided by NEC Corporation is the software module for NEC server products, to support remote management of installed software. ExpressUpdate Agent for Windows configures its named pipe with an improper access restriction.
    • Exposed IOCTL with Insufficient Access Control (CWE-782) - CVE-2026-8797
    MASAHIRO IIDA of LAC Co., Ltd. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000088.html",
      "dc:date": "2026-06-26T14:25+09:00",
      "dcterms:issued": "2026-06-26T14:25+09:00",
      "dcterms:modified": "2026-06-26T14:25+09:00",
      "description": "ExpressUpdate Agent for Windows provided by NEC Corporation is the software module for NEC server products, to support remote management of installed software.\r\nExpressUpdate Agent for Windows configures its named pipe with an improper access restriction.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/782.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://www.cve.org/CVERecord?id=CVE-2026-8797\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eExposed IOCTL with Insufficient Access Control (CWE-782) - CVE-2026-8797\u003c/li\u003e\u003c/ul\u003eMASAHIRO IIDA of LAC Co., Ltd. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000088.html",
      "sec:cpe": {
        "#text": "cpe:/a:nec:expressupdate_agent_for_windows",
        "@product": "ExpressUpdate Agent for Windows",
        "@vendor": "NEC Corporation",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "7.8",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2026-000088",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN35146924/index.html",
          "@id": "JVN#35146924",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-8797",
          "@id": "CVE-2026-8797",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "ExpressUpdate Agent for Windows improper access restriction on its named pipe"
    }

    JVNDB-2026-000079

    Vulnerability from jvndb - Published: 2026-05-25 06:35 - Updated:2026-05-25 09:14
    Severity
    Summary
    NEC Aterm series vulnerable to OS command injection (NV26-003)
    Details
    NEC Aterm series products provided by NEC Corporation contain the following vulnerability.
    • OS command injection (CWE-78) - CVE-2026-8652
    So Kato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000079.html",
      "dc:date": "2026-05-25T18:14+09:00",
      "dcterms:issued": "2026-05-25T15:35+09:00",
      "dcterms:modified": "2026-05-25T18:14+09:00",
      "description": "NEC Aterm series products provided by NEC Corporation contain the following vulnerability.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/78.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://www.cve.org/CVERecord?id=CVE-2026-8652\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eOS command injection (CWE-78) - CVE-2026-8652\u003c/li\u003e\u003c/ul\u003eSo Kato of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000079.html",
      "sec:cpe": [
        {
          "#text": "cpe:/o:nec:aterm_cm51fd",
          "@product": "Aterm CM51FD",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_mr51fn",
          "@product": "Aterm MR51FN",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "6.8",
        "@severity": "Medium",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2026-000079",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN80890147/index.html",
          "@id": "JVN#80890147",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-8652",
          "@id": "CVE-2026-8652",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        }
      ],
      "title": "NEC Aterm series vulnerable to OS command injection (NV26-003)"
    }

    JVNDB-2026-000078

    Vulnerability from jvndb - Published: 2026-05-25 06:35 - Updated:2026-05-25 09:06
    Severity
    Summary
    NEC Aterm series vulnerable to cross-site scripting (NV26-002)
    Details
    Aterm series products provided by NEC Corporation contain the following vulnerability.
    • Cross-site scripting (CWE-79) - CVE-2026-6059
    Noriaki Iwasaki of Cyber Defense Institute, Inc. reported this vulnerability to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000078.html",
      "dc:date": "2026-05-25T18:06+09:00",
      "dcterms:issued": "2026-05-25T15:35+09:00",
      "dcterms:modified": "2026-05-25T18:06+09:00",
      "description": "Aterm series products provided by NEC Corporation contain the following vulnerability.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/79.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://www.cve.org/CVERecord?id=CVE-2026-6059\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2026-6059\u003c/li\u003e\u003c/ul\u003eNoriaki Iwasaki of Cyber Defense Institute, Inc. reported this vulnerability to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000078.html",
      "sec:cpe": [
        {
          "#text": "cpe:/o:nec:aterm_19000t12be",
          "@product": "Aterm 19000T12BE",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_gx621a1",
          "@product": "Aterm GX621A1",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_sh621a1",
          "@product": "Aterm SH621A1",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wx11000t12",
          "@product": "Aterm WX11000T12",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wx1800hp",
          "@product": "Aterm WX1800HP",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wx3000hp2",
          "@product": "Aterm WX3000HP2",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wx4200d5",
          "@product": "Aterm WX4200D5",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wx5400hp",
          "@product": "Aterm WX5400HP",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wx7800t8",
          "@product": "Aterm WX7800T8",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "3.8",
        "@severity": "Low",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2026-000078",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN69049186/index.html",
          "@id": "JVN#69049186",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-6059",
          "@id": "CVE-2026-6059",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        }
      ],
      "title": "NEC Aterm series vulnerable to cross-site scripting (NV26-002)"
    }

    JVNDB-2026-000049

    Vulnerability from jvndb - Published: 2026-04-03 06:09 - Updated:2026-04-03 06:09
    Summary
    Multiple vulnerabilities in NEC Aterm series (NV26-001)
    Details
    Aterm series products provided by NEC Corporation contain multiple vulnerabilities listed below.
    • Missing authorization (CWE-862) - CVE-2026-4309
    • Path traversal (CWE-22) - CVE-2026-4619
    • OS command injection (CWE-78) - CVE-2026-4620, CVE-2026-4622
    • Hidden functionality (CWE-912) - CVE-2026-4621
    The vulnerabilities are reported from the following people, and JPCERT/CC coordinated with the developer. CVE-2026-4309 Taizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA. CVE-2026-4619, CVE-2026-4620, CVE-2026-4621, CVE-2026-4622 Chuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000049.html",
      "dc:date": "2026-04-03T15:09+09:00",
      "dcterms:issued": "2026-04-03T15:09+09:00",
      "dcterms:modified": "2026-04-03T15:09+09:00",
      "description": "Aterm series products provided by NEC Corporation contain multiple vulnerabilities listed below.\u003ca href=\u0027https://cwe.mitre.org/data/definitions/862.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://www.cve.org/CVERecord?id=CVE-2026-4309\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/22.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://www.cve.org/CVERecord?id=CVE-2026-4619\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/78.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027http://www.cve.org/CVERecord?id=CVE-2026-4620\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027http://www.cve.org/CVERecord?id=CVE-2026-4622\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027https://cwe.mitre.org/data/definitions/912.html\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003ca href=\u0027http://www.cve.org/CVERecord?id=CVE-2026-4621\u0027 target=\u0027_blank\u0027\u003e\u003c/a\u003e\u003cul\u003e\u003cli\u003eMissing authorization (CWE-862) - CVE-2026-4309\u003c/li\u003e\u003cli\u003ePath traversal (CWE-22) - CVE-2026-4619\u003c/li\u003e\u003cli\u003eOS command injection (CWE-78) - CVE-2026-4620, CVE-2026-4622\u003c/li\u003e\u003cli\u003eHidden functionality (CWE-912) - CVE-2026-4621\u003c/li\u003e\u003c/ul\u003eThe vulnerabilities are reported from the following people, and JPCERT/CC coordinated with the developer.\r\n\r\nCVE-2026-4309\r\nTaizoh Tsukamoto of Mitsui Bussan Secure Directions, Inc. reported this vulnerability to IPA.\r\n\r\nCVE-2026-4619, CVE-2026-4620, CVE-2026-4621, CVE-2026-4622\r\nChuya Hayakawa of 00One, Inc. reported these vulnerabilities to JPCERT/CC.",
      "link": "https://jvndb.jvn.jp/en/contents/2026/JVNDB-2026-000049.html",
      "sec:cpe": {
        "#text": "cpe:/o:nec:multiple_product",
        "@product": "(multiple product)",
        "@vendor": "NEC Corporation",
        "@version": "2.2"
      },
      "sec:identifier": "JVNDB-2026-000049",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN89339669/index.html",
          "@id": "JVN#89339669",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-4309",
          "@id": "CVE-2026-4309",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-4619",
          "@id": "CVE-2026-4619",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-4620",
          "@id": "CVE-2026-4620",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-4621",
          "@id": "CVE-2026-4621",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2026-4622",
          "@id": "CVE-2026-4622",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-22",
          "@title": "Path Traversal(CWE-22)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Multiple vulnerabilities in NEC Aterm series (NV26-001)"
    }

    JVNDB-2025-000107

    Vulnerability from jvndb - Published: 2025-11-19 07:22 - Updated:2025-11-19 07:22
    Severity
    Summary
    Installer of RakurakuMusen Start EX for Windows may insecurely load Dynamic Link Libraries
    Details
    Installer of RakurakuMusen Start EX for Windows provided by NEC Corporation uses an inappropriate DLL search path list, which may lead to insecurely loading Dynamic Link Libraries.
    • Uncontrolled search path element (CWE-427) - CVE-2025-12852
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000107.html",
      "dc:date": "2025-11-19T16:22+09:00",
      "dcterms:issued": "2025-11-19T16:22+09:00",
      "dcterms:modified": "2025-11-19T16:22+09:00",
      "description": "Installer of RakurakuMusen Start EX for Windows provided by NEC Corporation uses an inappropriate DLL search path list, which may lead to insecurely loading Dynamic Link Libraries.\u003cul\u003e\u003cli\u003eUncontrolled search path element (CWE-427) - CVE-2025-12852\u003c/li\u003e\u003c/ul\u003e",
      "link": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000107.html",
      "sec:cpe": {
        "#text": "cpe:/a:nec:rakuraku_wlanstart_ex",
        "@product": "RakurakuMusen Start EX",
        "@vendor": "NEC Corporation",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "7.8",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2025-000107",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN50288352/index.html",
          "@id": "JVN#50288352",
          "@source": "JVN"
        },
        {
          "#text": "https://jvn.jp/en/ta/JVNTA91240916/",
          "@id": "Japan Vulnerability Notes JVNTA#91240916",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-12852",
          "@id": "CVE-2025-12852",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Installer of RakurakuMusen Start EX for Windows may insecurely load Dynamic Link Libraries"
    }

    JVNDB-2025-000102

    Vulnerability from jvndb - Published: 2025-11-07 05:55 - Updated:2025-11-07 05:55
    Severity
    Summary
    CLUSTERPRO X and EXPRESSCLUSTER X vulnerable to OS command injection
    Details
    CLUSTERPRO X and EXPRESSCLUSTER X provided by NEC Corporation contain the following vulnerability. * OS command injection (CWE-78) - CVE-2025-11546 NEC Corporation reported this vulnerability to IPA to notify users of its solution through JVN. JPCERT/CC and NEC Corporation coordinated under the Information Security Early Warning Partnership.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000102.html",
      "dc:date": "2025-11-07T14:55+09:00",
      "dcterms:issued": "2025-11-07T14:55+09:00",
      "dcterms:modified": "2025-11-07T14:55+09:00",
      "description": "CLUSTERPRO X and EXPRESSCLUSTER X provided by NEC Corporation contain the following vulnerability.\r\n\r\n* OS command injection (CWE-78) - CVE-2025-11546\r\n\r\nNEC Corporation reported this vulnerability to IPA to notify users of its solution through JVN. JPCERT/CC and NEC Corporation coordinated under the Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000102.html",
      "sec:cpe": [
        {
          "#text": "cpe:/a:nec:clusterpro_x_misc",
          "@product": "CLUSTERPRO X",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:nec:clusterpro_x_singleserversafe_misc",
          "@product": "CLUSTERPRO X SingleServerSafe",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:nec:expresscluster_x",
          "@product": "EXPRESSCLUSTER X",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:nec:expresscluster_x_singleserversafe",
          "@product": "EXPRESSCLUSTER X SingleServerSafe",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "9.8",
        "@severity": "Critical",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2025-000102",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN59387134/index.html",
          "@id": "JVN#59387134",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-11546",
          "@id": "CVE-2025-11546",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        }
      ],
      "title": "CLUSTERPRO X and EXPRESSCLUSTER X vulnerable to OS command injection"
    }

    JVNDB-2025-000079

    Vulnerability from jvndb - Published: 2025-09-18 08:43 - Updated:2025-09-18 08:43
    Severity
    Summary
    UNIVERGE IX/IX-R/IX-V series routers provided by NEC Corporation vulnerable to cross-site scripting
    Details
    UNIVERGE IX/IX-R/IX-V series routers provided by NEC Corporation contains the following vulnerability.
    • Cross-site scripting (CWE-79) - CVE-2025-8153
    RyotaK of GMO Flatt Security Inc. reported this vulnerability to NEC Corporation and coordinated. After the coordination was completed, NEC Corporation reported the case to IPA to notify users of the solution through JVN.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000079.html",
      "dc:date": "2025-09-18T17:43+09:00",
      "dcterms:issued": "2025-09-18T17:43+09:00",
      "dcterms:modified": "2025-09-18T17:43+09:00",
      "description": "UNIVERGE IX/IX-R/IX-V series routers provided by NEC Corporation contains the following vulnerability.\r\n\u003cul\u003e\u003cli\u003eCross-site scripting (CWE-79) - CVE-2025-8153\u003c/li\u003e\u003c/ul\u003e\r\nRyotaK of GMO Flatt Security Inc. reported this vulnerability to NEC Corporation and coordinated.\r\nAfter the coordination was completed, NEC Corporation reported the case to IPA to notify users of the solution through JVN.",
      "link": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000079.html",
      "sec:cpe": {
        "#text": "cpe:/o:nec:univerge",
        "@product": "UNIVERGE",
        "@vendor": "NEC Corporation",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "6.1",
        "@severity": "Medium",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2025-000079",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN95938761/index.html",
          "@id": "JVN#95938761",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-8153",
          "@id": "CVE-2025-8153",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        }
      ],
      "title": "UNIVERGE IX/IX-R/IX-V series routers provided by NEC Corporation vulnerable to cross-site scripting"
    }

    JVNDB-2025-000002

    Vulnerability from jvndb - Published: 2025-02-14 06:48 - Updated:2025-02-14 06:48
    Severity
    Summary
    Multiple vulnerabilities in NEC Aterm series (NV25-003)
    Details
    Aterm series provided by NEC Corporation contains multiple vulnerabilities listed below.
    • Stored Cross-site Scripting (CWE-79) - CVE-2025-0354
    • Missing Authentication for Critical Function (CWE-306) - CVE-2025-0355
    • OOS Command Injection (CWE-78) - CVE-2025-0356
    CVE-2025-0354, CVE-2025-0355 Takayuki Sasaki and Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to JPCERT/CC. JPCERT/CC coordinated with the developer. CVE-2025-0356 Kakeru Kajihara of NTT Security Holdings reported this vulnerability to JPCERT/CC. JPCERT/CC coordinated with the developer.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000002.html",
      "dc:date": "2025-02-14T15:48+09:00",
      "dcterms:issued": "2025-02-14T15:48+09:00",
      "dcterms:modified": "2025-02-14T15:48+09:00",
      "description": "Aterm series provided by NEC Corporation contains multiple vulnerabilities listed below.\r\n\r\n\u003cul\u003e\r\n\u003cli\u003eStored Cross-site Scripting (CWE-79) - CVE-2025-0354\u003c/li\u003e\r\n\u003cli\u003eMissing Authentication for Critical Function (CWE-306) - CVE-2025-0355\u003c/li\u003e\r\n\u003cli\u003eOOS Command Injection (CWE-78) - CVE-2025-0356\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\r\nCVE-2025-0354, CVE-2025-0355\r\nTakayuki Sasaki and Katsunari Yoshioka of Yokohama National University reported these vulnerabilities to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.\r\n\r\nCVE-2025-0356\r\nKakeru Kajihara of NTT Security Holdings reported this vulnerability to JPCERT/CC.\r\nJPCERT/CC coordinated with the developer.",
      "link": "https://jvndb.jvn.jp/en/contents/2025/JVNDB-2025-000002.html",
      "sec:cpe": [
        {
          "#text": "cpe:/o:nec:aterm_gb1200pe_firmware",
          "@product": "Aterm GB1200PE firmware",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wf1200cr_firmware",
          "@product": "Aterm WF1200CR firmware",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1200cr_firmware",
          "@product": "Aterm WG1200CR firmware",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg2600hm4_firmware",
          "@product": "Aterm WG2600HM4 firmware",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg2600hp4_firmware",
          "@product": "Aterm WG2600HP4 firmware",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg2600hs2_firmware",
          "@product": "Aterm WG2600HS2 firmware",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg2600hs_firmware",
          "@product": "Aterm WG2600HS firmware",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wx1500hp_firmware",
          "@product": "Aterm WX1500HP firmware",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wx3000hp_firmware",
          "@product": "Aterm WX3000HP firmware",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wx3000hp_firmware",
          "@product": "Aterm WX3000HP firmware",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wx3600hp_firmware",
          "@product": "Aterm WX3600HP firmware",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wx4200d5_firmware",
          "@product": "Aterm WX4200D5 firmware",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "7.5",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2025-000002",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN65447879/index.html",
          "@id": "JVN#65447879",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-0354",
          "@id": "CVE-2025-0354",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-0355",
          "@id": "CVE-2025-0355",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2025-0356",
          "@id": "CVE-2025-0356",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-79",
          "@title": "Cross-site Scripting(CWE-79)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Multiple vulnerabilities in NEC Aterm series (NV25-003)"
    }

    JVNDB-2024-000124

    Vulnerability from jvndb - Published: 2024-12-02 07:38 - Updated:2024-12-02 07:38
    Severity
    Summary
    Multiple vulnerabilities in UNIVERGE IX/IX-R/IX-V series routers
    Details
    UNIVERGE IX/IX-R/IX-V series routers provided by NEC Corporation contain multiple vulnerabilities listed below.
    • Command injection (CWE-77) - CVE-2024-11013
    • Cross-site request forgery (WE-352) - CVE-2024-11014
    RyotaK of Flatt Security Inc. reported these vulnerabilities to NEC Corporation and coordinated. NEC Corporation and JPCERT/CC published respective advisories in order to notify users of the solutions through JVN.
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-000124.html",
      "dc:date": "2024-12-02T16:38+09:00",
      "dcterms:issued": "2024-12-02T16:38+09:00",
      "dcterms:modified": "2024-12-02T16:38+09:00",
      "description": "UNIVERGE IX/IX-R/IX-V series routers provided by NEC Corporation contain multiple vulnerabilities listed below.\r\n\u003cul\u003e\u003cli\u003eCommand injection (CWE-77) - CVE-2024-11013\u003c/li\u003e\u003cli\u003eCross-site request forgery (WE-352) - CVE-2024-11014\u003c/li\u003e\u003c/ul\u003e\r\n\r\nRyotaK of Flatt Security Inc. reported these vulnerabilities to NEC Corporation and coordinated. NEC Corporation and JPCERT/CC published respective advisories in order to notify users of the solutions through JVN.",
      "link": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-000124.html",
      "sec:cpe": {
        "#text": "cpe:/o:nec:univerge",
        "@product": "UNIVERGE",
        "@vendor": "NEC Corporation",
        "@version": "2.2"
      },
      "sec:cvss": {
        "@score": "7.2",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2024-000124",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN53958863/index.html",
          "@id": "JVN#53958863",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-11013",
          "@id": "CVE-2024-11013",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-11014",
          "@id": "CVE-2024-11014",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-352",
          "@title": "Cross-Site Request Forgery(CWE-352)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Multiple vulnerabilities in UNIVERGE IX/IX-R/IX-V series routers"
    }

    JVNDB-2024-000077

    Vulnerability from jvndb - Published: 2024-07-30 07:40 - Updated:2024-07-30 07:40
    Severity
    Summary
    FFRI AMC vulnerable to OS command injection
    Details
    FFRI AMC provided by FFRI Security, Inc. is a management console for the endpoint security product FFRI yarai and ActSecure X. FFRI AMC contains an OS command injection vulnerability (CWE-78). It is exploitable when the notification program setting is enabled, the executable file path is configured with a batch file (.bat) or command file (.cmd), and the file is written in a certain style. FFRI Security, Inc. reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and FFRI Security, Inc. coordinated under the Information Security Early Warning Partnership.
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-000077.html",
      "dc:date": "2024-07-30T16:40+09:00",
      "dcterms:issued": "2024-07-30T16:40+09:00",
      "dcterms:modified": "2024-07-30T16:40+09:00",
      "description": "FFRI AMC provided by FFRI Security, Inc. is a management console for the endpoint security product FFRI yarai and ActSecure X.\r\nFFRI AMC contains an OS command injection vulnerability (CWE-78).\r\nIt is exploitable when the notification program setting is enabled, the executable file path is configured with a batch file (.bat) or command file (.cmd), and the file is written in a certain style.\r\n\r\nFFRI Security, Inc. reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and FFRI Security, Inc. coordinated under the Information Security Early Warning Partnership.",
      "link": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-000077.html",
      "sec:cpe": [
        {
          "#text": "cpe:/a:ffri:ffri_amc",
          "@product": "FFRI AMC",
          "@vendor": "FFRI Security, Inc.",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:nec:ffri_amc",
          "@product": "FFRI AMC for ActSecure X",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/a:skygroup:edr_plus_pack",
          "@product": "EDR Pluspack",
          "@vendor": "Sky Co., LTD.",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "8.1",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2024-000077",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN26734798/index.html",
          "@id": "JVN#26734798",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-40895",
          "@id": "CVE-2024-40895",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        }
      ],
      "title": "FFRI AMC vulnerable to OS command injection"
    }

    JVNDB-2024-003181

    Vulnerability from jvndb - Published: 2024-05-10 04:59 - Updated:2024-05-10 04:59
    Summary
    Hidden Functionality vulnerability in DT900
    Details
    DT900 contains a Hidden Functionality vulnerability(CWE-912). Specified versions allow an attacker to access the system setting. reported by Mr. Gianluca Altomani and Mr. Manuel Romei. for NEC-PSIRT
    Impacted products
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-003181.html",
      "dc:date": "2024-05-10T13:59+09:00",
      "dcterms:issued": "2024-05-10T13:59+09:00",
      "dcterms:modified": "2024-05-10T13:59+09:00",
      "description": "DT900 contains a Hidden Functionality vulnerability(CWE-912).  Specified versions allow an attacker to access the system setting.\r\n\r\nreported by Mr. Gianluca Altomani and Mr. Manuel Romei. for NEC-PSIRT",
      "link": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-003181.html",
      "sec:cpe": {
        "#text": "cpe:/o:nec:dt900",
        "@product": "DT900",
        "@vendor": "NEC Corporation",
        "@version": "2.2"
      },
      "sec:identifier": "JVNDB-2024-003181",
      "sec:references": [
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-3016",
          "@id": "CVE-2024-3016",
          "@source": "CVE"
        },
        {
          "#text": "https://cwe.mitre.org/data/definitions/912.html",
          "@id": "CWE-912",
          "@title": "Hidden Functionality(CWE-912)"
        }
      ],
      "title": "Hidden Functionality vulnerability in DT900"
    }

    JVNDB-2024-000037

    Vulnerability from jvndb - Published: 2024-04-05 05:53 - Updated:2024-04-05 05:53
    Severity
    Summary
    Multiple vulnerabilities in NEC Aterm series
    Details
    Aterm series provided by NEC Corporation contains multiple vulnerabilities listed below.
    • Incorrect Permission Assignment for Critical Resource (CWE-732) - CVE-2024-28005
    • Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) - CVE-2024-28006
    • Incorrect Permission Assignment for Critical Resource (CWE-732) - CVE-2024-28007
    • Active Debug Code (CWE-489) - CVE-2024-28008
    • Use of Weak Credentials (CWE-1391) - CVE-2024-28009, CVE-2024-28012
    • Use of Hard-coded Credentials (CWE-798) - CVE-2024-28010
    • Inclusion of Undocumented Features (CWE-1242) - CVE-2024-28011
    • Insufficient Session Expiration (CWE-613) - CVE-2024-28013
    • Buffer Overflow (CWE-120) - CVE-2024-28014
    • OS Command Injection in the web management console (CWE-78) - CVE-2024-28015
    • Exposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) - CVE-2024-28016
    The following people reported the vulnerabilities to IPA. JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership. CVE-2024-28005, CVE-2024-28008 Ryo Kashiro, and Katsuhiko Sato, and Takayuki Sasaki, and Katsunari Yoshioka of Yokohama National University CVE-2024-28006, CVE-2024-28007, CVE-2024-28009, CVE-2024-28010, CVE-2024-28011, CVE-2024-28012 Ryo Kashiro, and Katsuhiko Sato CVE-2024-28013 Yudai Morii, Takaya Noma, Takayuki Sasaki, and Katsunari Yoshioka of Yokohama National University CVE-2024-28014, CVE-2024-28015, CVE-2024-28016 Takayuki Sasaki, and Katsunari Yoshioka of Yokohama National University
    Impacted products
    NEC Corporation Aterm WM3400RN
    NEC Corporation Aterm WM3450RN
    NEC Corporation Aterm WM3600R
    NEC Corporation Aterm WR8160N
    NEC Corporation Aterm CR2500P
    NEC Corporation Aterm MR01LN
    NEC Corporation Aterm MR02LN
    NEC Corporation Aterm W1200EX(-MS)
    NEC Corporation Aterm W300P
    NEC Corporation Aterm WF1200HP
    NEC Corporation Aterm WF1200HP2
    NEC Corporation Aterm WF300HP2
    NEC Corporation Aterm WF300HP
    NEC Corporation Aterm WF800HP
    NEC Corporation Aterm WG1200HP2
    NEC Corporation Aterm WG1200HP3
    NEC Corporation Aterm WG1200HP
    NEC Corporation Aterm WG1200HS2
    NEC Corporation Aterm WG1200HS3
    NEC Corporation Aterm WG1200HS
    NEC Corporation Aterm WG1400HP
    NEC Corporation Aterm WG1800HP2
    NEC Corporation Aterm WG1800HP3
    NEC Corporation Aterm WG1800HP4
    NEC Corporation Aterm WG1800HP
    NEC Corporation Aterm WG1810HP(JE)
    NEC Corporation Aterm WG1810HP(MF)
    NEC Corporation Aterm WG1900HP2
    NEC Corporation Aterm WG1900HP
    NEC Corporation Aterm WG2200HP
    NEC Corporation Aterm WG300HP
    NEC Corporation Aterm WG600HP
    NEC Corporation Aterm WM3500R
    NEC Corporation Aterm WM3800R
    NEC Corporation Aterm WR1200H
    NEC Corporation Aterm WR4100N
    NEC Corporation Aterm WR4500N
    NEC Corporation Aterm WR6600H
    NEC Corporation Aterm WR6650S
    NEC Corporation Aterm WR6670S
    NEC Corporation Aterm WR7800H
    NEC Corporation Aterm WR7850S
    NEC Corporation Aterm WR7870S
    NEC Corporation Aterm WR8100N
    NEC Corporation Aterm WR8150N
    NEC Corporation Aterm WR8165N
    NEC Corporation Aterm WR8166N
    NEC Corporation Aterm WR8170N
    NEC Corporation Aterm WR8175N
    NEC Corporation Aterm WR8200N
    NEC Corporation Aterm WR8300N
    NEC Corporation Aterm WR8370N
    NEC Corporation Aterm WR8400N
    NEC Corporation Aterm WR8500N
    NEC Corporation Aterm WR8600N
    NEC Corporation Aterm WR8700N
    NEC Corporation Aterm WR8750N
    NEC Corporation Aterm WR9300N
    NEC Corporation Aterm WR9500N
    Show details on JVN DB website

    {
      "@rdf:about": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-000037.html",
      "dc:date": "2024-04-05T14:53+09:00",
      "dcterms:issued": "2024-04-05T14:53+09:00",
      "dcterms:modified": "2024-04-05T14:53+09:00",
      "description": "Aterm series provided by NEC Corporation contains multiple vulnerabilities listed below.\r\n\r\n\u003cul\u003e\r\n\u003cli\u003eIncorrect Permission Assignment for Critical Resource (CWE-732) - CVE-2024-28005\u003c/li\u003e\r\n\u003cli\u003eExposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) - CVE-2024-28006\u003c/li\u003e\r\n\u003cli\u003eIncorrect Permission Assignment for Critical Resource (CWE-732) - CVE-2024-28007\u003c/li\u003e\r\n\u003cli\u003eActive Debug Code (CWE-489) - CVE-2024-28008\u003c/li\u003e\r\n\u003cli\u003eUse of Weak Credentials (CWE-1391) - CVE-2024-28009, CVE-2024-28012\u003c/li\u003e\r\n\u003cli\u003eUse of Hard-coded Credentials (CWE-798) - CVE-2024-28010\u003c/li\u003e\r\n\u003cli\u003eInclusion of Undocumented Features (CWE-1242) - CVE-2024-28011\u003c/li\u003e\r\n\u003cli\u003eInsufficient Session Expiration (CWE-613) - CVE-2024-28013\u003c/li\u003e\r\n\u003cli\u003eBuffer Overflow (CWE-120) - CVE-2024-28014\u003c/li\u003e\r\n\u003cli\u003eOS Command Injection in the web management console (CWE-78) - CVE-2024-28015\u003c/li\u003e\r\n\u003cli\u003eExposure of Sensitive System Information to an Unauthorized Control Sphere (CWE-497) - CVE-2024-28016\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\r\nThe following people reported the vulnerabilities to IPA.\r\nJPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.\r\n\r\nCVE-2024-28005, CVE-2024-28008\r\nRyo Kashiro, and Katsuhiko Sato, and Takayuki Sasaki, and Katsunari Yoshioka of Yokohama National University\r\n\r\nCVE-2024-28006, CVE-2024-28007, CVE-2024-28009, CVE-2024-28010, CVE-2024-28011, CVE-2024-28012\r\nRyo Kashiro, and Katsuhiko Sato\r\n\r\nCVE-2024-28013\r\nYudai Morii, Takaya Noma, Takayuki Sasaki, and Katsunari Yoshioka of Yokohama National University\r\n\r\nCVE-2024-28014, CVE-2024-28015, CVE-2024-28016\r\nTakayuki Sasaki, and Katsunari Yoshioka of Yokohama National University",
      "link": "https://jvndb.jvn.jp/en/contents/2024/JVNDB-2024-000037.html",
      "sec:cpe": [
        {
          "#text": "cpe:/h:nec:atermwm3400rn",
          "@product": "Aterm WM3400RN",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:nec:atermwm3450rn",
          "@product": "Aterm WM3450RN",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:nec:atermwm3600r",
          "@product": "Aterm WM3600R",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/h:nec:atermwr8160n",
          "@product": "Aterm WR8160N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_cr2500p",
          "@product": "Aterm CR2500P",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_mr01ln",
          "@product": "Aterm MR01LN",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_mr02ln",
          "@product": "Aterm MR02LN",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_w1200ex(-ms)",
          "@product": "Aterm W1200EX(-MS)",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_w300p_firmware",
          "@product": "Aterm W300P",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wf1200hp",
          "@product": "Aterm WF1200HP",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wf1200hp2",
          "@product": "Aterm WF1200HP2",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wf300hp2_firmware",
          "@product": "Aterm WF300HP2",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wf300hp_firmware",
          "@product": "Aterm WF300HP",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wf800hp_firmware",
          "@product": "Aterm WF800HP",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1200hp2_firmware",
          "@product": "Aterm WG1200HP2",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1200hp3_firmware",
          "@product": "Aterm WG1200HP3",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1200hp_firmware",
          "@product": "Aterm WG1200HP",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1200hs2_firmware",
          "@product": "Aterm WG1200HS2",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1200hs3_firmware",
          "@product": "Aterm WG1200HS3",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1200hs_firmware",
          "@product": "Aterm WG1200HS",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1400hp_firmware",
          "@product": "Aterm WG1400HP",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1800hp2_firmware",
          "@product": "Aterm WG1800HP2",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1800hp3_firmware",
          "@product": "Aterm WG1800HP3",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1800hp4_firmware",
          "@product": "Aterm WG1800HP4",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1800hp_firmware",
          "@product": "Aterm WG1800HP",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1810hp(je)",
          "@product": "Aterm WG1810HP(JE)",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1810hp(mf)",
          "@product": "Aterm WG1810HP(MF)",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1900hp2_firmware",
          "@product": "Aterm WG1900HP2",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg1900hp_firmware",
          "@product": "Aterm WG1900HP",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg2200hp_firmware",
          "@product": "Aterm WG2200HP",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg300hp_firmware",
          "@product": "Aterm WG300HP",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wg600hp_firmware",
          "@product": "Aterm WG600HP",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wm3500r",
          "@product": "Aterm WM3500R",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wm3800r",
          "@product": "Aterm WM3800R",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr1200h",
          "@product": "Aterm WR1200H",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr4100n",
          "@product": "Aterm WR4100N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr4500n",
          "@product": "Aterm WR4500N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr6600h",
          "@product": "Aterm WR6600H",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr6650s",
          "@product": "Aterm WR6650S",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr6670s",
          "@product": "Aterm WR6670S",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr7800h",
          "@product": "Aterm WR7800H",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr7850s",
          "@product": "Aterm WR7850S",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr7870s",
          "@product": "Aterm WR7870S",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8100n",
          "@product": "Aterm WR8100N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8150n",
          "@product": "Aterm WR8150N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8165n_firmware",
          "@product": "Aterm WR8165N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8166n",
          "@product": "Aterm WR8166N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8170n_firmware",
          "@product": "Aterm WR8170N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8175n_firmware",
          "@product": "Aterm WR8175N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8200n",
          "@product": "Aterm WR8200N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8300n",
          "@product": "Aterm WR8300N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8370n_firmware",
          "@product": "Aterm WR8370N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8400n",
          "@product": "Aterm WR8400N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8500n",
          "@product": "Aterm WR8500N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8600n_firmware",
          "@product": "Aterm WR8600N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8700n_firmware",
          "@product": "Aterm WR8700N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr8750n_firmware",
          "@product": "Aterm WR8750N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr9300n_firmware",
          "@product": "Aterm WR9300N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        },
        {
          "#text": "cpe:/o:nec:aterm_wr9500n_firmware",
          "@product": "Aterm WR9500N",
          "@vendor": "NEC Corporation",
          "@version": "2.2"
        }
      ],
      "sec:cvss": {
        "@score": "8.8",
        "@severity": "High",
        "@type": "Base",
        "@vector": "CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
        "@version": "3.0"
      },
      "sec:identifier": "JVNDB-2024-000037",
      "sec:references": [
        {
          "#text": "https://jvn.jp/en/jp/JVN82074338/index.html",
          "@id": "JVN#82074338",
          "@source": "JVN"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-28005",
          "@id": "CVE-2024-28005",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-28006",
          "@id": "CVE-2024-28006",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-28007",
          "@id": "CVE-2024-28007",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-28008",
          "@id": "CVE-2024-28008",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-28009",
          "@id": "CVE-2024-28009",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-28010",
          "@id": "CVE-2024-28010",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-28011",
          "@id": "CVE-2024-28011",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-28012",
          "@id": "CVE-2024-28012",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-28013",
          "@id": "CVE-2024-28013",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-28014",
          "@id": "CVE-2024-28014",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-28015",
          "@id": "CVE-2024-28015",
          "@source": "CVE"
        },
        {
          "#text": "https://www.cve.org/CVERecord?id=CVE-2024-280016",
          "@id": "CVE-2024-28016",
          "@source": "CVE"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-119",
          "@title": "Buffer Errors(CWE-119)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-200",
          "@title": "Information Exposure(CWE-200)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-287",
          "@title": "Improper Authentication(CWE-287)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-78",
          "@title": "OS Command Injection(CWE-78)"
        },
        {
          "#text": "https://www.ipa.go.jp/en/security/vulnerabilities/cwe.html",
          "@id": "CWE-Other",
          "@title": "No Mapping(CWE-Other)"
        }
      ],
      "title": "Multiple vulnerabilities in NEC Aterm series"
    }