CVE-2026-6059 PUBLISHED

Assigner: NEC
Reserved: 10.04.2026 Published: 25.05.2026 Updated: 25.05.2026

A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 4.8

Product Status

Vendor NEC Platforms, Ltd.
Product Aterm WX1800HP
Versions Default: unknown
  • Version Before Ver. 3.2.2 is affected
Vendor NEC Platforms, Ltd.
Product Aterm WX5400HP
Versions Default: unknown
  • Version Before Ver. 2.1.0 is affected
Vendor NEC Platforms, Ltd.
Product Aterm WX7800T8
Versions Default: unknown
  • Version Before Ver. 1.5.1 is affected
Vendor NEC Platforms, Ltd.
Product Aterm WX11000T12
Versions Default: unknown
  • Version Before Ver. 1.4.0 is affected
Vendor NEC Platforms, Ltd.
Product Aterm WX3000HP2
Versions Default: unknown
  • Version Before Ver. 1.3.2 is affected
Vendor NEC Platforms, Ltd.
Product Aterm WX4200D5
Versions Default: unknown
  • Version Before Ver. 1.3.5 is affected
Vendor NEC Platforms, Ltd.
Product Aterm GX621A1
Versions Default: unknown
  • Version Before Ver. 3.2.2 is affected
Vendor NEC Platforms, Ltd.
Product Aterm SH621A1
Versions Default: unknown
  • Version Before Ver. 3.2.2 is affected
Vendor NEC Platforms, Ltd.
Product Aterm 19000T12BE
Versions Default: unknown
  • Version Before Ver. 1.1.0 is affected

Credits

  • Noriaki Iwasaki of Cyber Defense Institute, Inc. reporter

References

Problem Types

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE