CVE-2026-8652 PUBLISHED

Assigner: NEC
Reserved: 15.05.2026 Published: 25.05.2026 Updated: 25.05.2026

An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjacent network.

Metrics

CVSS Vector: CVSS:4.0/AV:A/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor NEC Platforms, Ltd.
Product Aterm MR51FN
Versions Default: unknown
  • Version Before Ver. 3.4.0 is affected
Vendor NEC Platforms, Ltd.
Product Aterm CM51FD
Versions Default: unknown
  • Version Before Ver. 1.2.0 is affected

Credits

  • Sou Katou of Mitsui & Co. Secure Direction, Inc. reporter

References

Problem Types

  • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CWE