VYPR

Vendor CVEs

NEC

All CVEs

150 total · sorted by risk
  • CVE-2025-12852HigNov 19, 2025
    risk 0.55cvss epss 0.00

    DLL Loading vulnerability in NEC Corporation RakurakuMusen Start EX All Verisons allows a attacker to manipulate the PC environment to cause unintended operations on the user's device.

  • CVE-2020-17408HigSep 10, 2020
    risk 0.55cvss 7.5epss 0.74

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vulnerability. The specific flaw exists within the clpwebmc executable. Due to the improper…

  • CVE-2020-5534HigFeb 21, 2020
    risk 0.52cvss 8.0epss 0.01

    Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via unspecified vectors.

  • CVE-2020-5525HigFeb 21, 2020
    risk 0.52cvss 8.0epss 0.01

    Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via…

  • CVE-2025-22022HigApr 16, 2025
    risk 0.51cvss 7.8epss 0.00

    In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Apply the link chain quirk on NEC isoc endpoints Two clearly different specimens of NEC uPD720200 (one with start/stop bug, one without) were seen to cause IOMMU faults after some Missed Service…

  • CVE-2023-25011HigFeb 15, 2023
    risk 0.51cvss 7.8epss 0.00

    PC settings tool Ver10.1.26.0 and earlier, PC settings tool Ver11.0.22.0 and earlier allows a attacker to write to the registry as administrator privileges with standard user privileges.

  • CVE-2020-5632HigOct 6, 2020
    risk 0.51cvss 7.8epss 0.00

    InfoCage SiteShell series (Host type SiteShell for IIS V1.4, V1.5, and V1.6, Host type SiteShell for IIS prior to revision V2.0.0.6, V2.1.0.7, V2.1.1.6, V3.0.0.11, V4.0.0.6, V4.1.0.5, and V4.2.0.1, Host type SiteShell for Apache Windows V1.4, V1.5, and V1.6, and Host type…

  • CVE-2019-20030HigJul 29, 2020
    risk 0.51cvss 7.8epss 0.00

    An attacker with knowledge of the modem access number on a NEC UM8000 voicemail system may use SSH tunneling or standard Linux utilities to gain access to the system's LAN port. All versions are affected.

  • CVE-2020-12695HigJun 8, 2020
    risk 0.50cvss 7.5epss 0.15

    The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.

  • CVE-2025-0355HigJan 15, 2025
    risk 0.49cvss 7.5epss 0.01

    Missing Authentication for Critical Function vulnerability in NEC Corporation Aterm WG2600HS Ver.1.7.2 and earlier, WF1200CRS Ver.1.6.0 and earlier, WG1200CRS Ver.1.5.0 and earlier, GB1200PE Ver.1.3.0 and earlier, WG2600HP4 Ver.1.4.2 and earlier, WG2600HM4 Ver.1.4.2 and earlier,…

  • CVE-2021-20707HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper input validation vulnerability in the Transaction Server CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier…

  • CVE-2021-20706HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows…

  • CVE-2021-20705HigNov 3, 2021
    risk 0.49cvss 7.5epss 0.01

    Improper input validation vulnerability in the WebManager CLUSTERPRO X 4.3 for Windows and earlier, EXPRESSCLUSTER X 4.3 for Windows and earlier, CLUSTERPRO X 4.3 SingleServerSafe for Windows and earlier, EXPRESSCLUSTER X 4.3 SingleServerSafe for Windows and earlier allows…

  • CVE-2020-27859HigJan 20, 2021
    risk 0.49cvss 7.5epss 0.03

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the GetEuaLogDownloadAction class. The issue results…

  • CVE-2020-5686HigJan 13, 2021
    risk 0.49cvss 7.5epss 0.01

    Incorrect implementation of authentication algorithm issue in UNIVERGE SV9500 series from V1 to V7and SV8500 series from S6 to S8 allows an attacker to access the remote system maintenance feature and obtain the information by sending a specially crafted request to a specific…

  • CVE-2019-20028HigJul 29, 2020
    risk 0.49cvss 7.5epss 0.01

    Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices allow unauthenticated read-only access to voicemails, greetings, and voice response system content through a system's WebPro administration interface.

  • CVE-2019-20026HigJul 29, 2020
    risk 0.49cvss 7.5epss 0.01

    The WebPro interface in NEC SV9100 software releases 7.0 or higher allows unauthenticated remote attackers to reset all existing usernames and passwords to default values via a crafted request.

  • CVE-2017-12575HigAug 24, 2018
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered on the NEC Aterm WG2600HP2 1.0.2. The router has a set of web service APIs for access to and setup of the configuration. Some APIs don't require authentication. An attacker could exploit this vulnerability by sending a crafted HTTP request to retrieve…

  • CVE-2016-1145HigJan 30, 2016
    risk 0.49cvss 7.5epss 0.04

    Directory traversal vulnerability in WebManager in NEC EXPRESSCLUSTER X through 3.3 11.31 on Windows and through 3.3 3.3.1-1 on Linux and Solaris allows remote attackers to read arbitrary files via unspecified vectors.

  • CVE-2025-0356HigJan 15, 2025
    risk 0.47cvss 7.2epss 0.01

    NEC Corporation Aterm WX1500HP Ver.1.4.2 and earlier and WX3600HP Ver.1.5.3 and earlier allows a attacker to execute arbitrary OS commands via the network.

  • CVE-2024-11013HigNov 29, 2024
    risk 0.47cvss 7.2epss 0.01

    Command Injection vulnerability in NEC Corporation UNIVERGE IX from Ver9.2 to Ver10.10.21, for Ver10.8 up to Ver10.8.27, for Ver10.9 up to Ver10.9.14 and UNIVERGE IX-R/IX-V Ver1.2.15 and earlier allows a attacker to inject an arbitrary CLI commands to be executed on the device…

  • CVE-2023-3333HigJun 28, 2023
    risk 0.47cvss 7.2epss 0.01

    Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all…

  • CVE-2021-20709HigApr 26, 2021
    risk 0.47cvss 7.2epss 0.01

    Improper validation of integrity check value vulnerability in NEC Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm WG2600HS firmware Ver1.5.1 and earlier allows an attacker with an administrative privilege to execute arbitrary…

  • CVE-2021-20708HigApr 26, 2021
    risk 0.47cvss 7.2epss 0.01

    NEC Aterm devices (Aterm WF1200CR firmware Ver1.3.2 and earlier, Aterm WG1200CR firmware Ver1.3.3 and earlier, and Aterm WG2600HS firmware Ver1.5.1 and earlier) allow authenticated attackers to execute arbitrary OS commands by sending a specially crafted request to a specific…

  • CVE-2018-16194HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.

  • CVE-2018-0641HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.02

    Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via tools_system.cgi date parameter, time parameter, and offset parameter.

  • CVE-2018-0640HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.02

    Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date parameter, time parameter, and offset parameter.

  • CVE-2018-0639HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via tools_firmware.cgi date parameter, time parameter, and offset parameter.

  • CVE-2018-0638HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameter.

  • CVE-2018-0637HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via export.cgi encKey parameter.

  • CVE-2018-0636HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter of a certain URL, different URL from CVE-2018-0634.

  • CVE-2018-0635HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via filename parameter.

  • CVE-2018-0634HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter or bootmode parameter of a certain URL.

  • CVE-2018-0633HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.02

    Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via submit-url parameter.

  • CVE-2018-0632HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.02

    Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via HTTP request and response.

  • CVE-2018-0631HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.

  • CVE-2018-0630HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd parameter.

  • CVE-2018-0629HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.

  • CVE-2018-0628HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.

  • CVE-2018-0627HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.

  • CVE-2018-0626HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd in formWsc parameter.

  • CVE-2018-0625HigJan 9, 2019
    risk 0.47cvss 7.2epss 0.01

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via formSysCmd parameter.

  • CVE-2020-5637MedDec 14, 2020
    risk 0.44cvss 6.8epss 0.00

    Improper validation of integrity check value vulnerability in Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to execute a malicious program.

  • CVE-2020-5636MedDec 14, 2020
    risk 0.44cvss 6.8epss 0.01

    Aterm SA3500G firmware versions prior to Ver. 3.5.9 allows an attacker with an administrative privilege to send a specially crafted request to a specific URL, which may result in an arbitrary command execution.

  • CVE-2026-4309MedMar 27, 2026
    risk 0.42cvss 6.5epss 0.00

    Missing Authorization vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to get a specific device information and change the settings via network.

  • CVE-2019-20032MedJul 29, 2020
    risk 0.42cvss 6.5epss 0.01

    An attacker with access to an InMail voicemail box equipped with the find me/follow me feature on Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices, may access the system's administration modem.

  • CVE-2018-16192MedJan 9, 2019
    risk 0.42cvss 6.5epss 0.01

    Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allow an attacker on the same network segment to obtain information registered on the device via unspecified vectors.

  • CVE-2021-20710MedApr 26, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.5.1 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.

  • CVE-2021-20680MedApr 26, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in NEC Aterm devices (Aterm WG1900HP2 firmware Ver.1.3.1 and earlier, Aterm WG1900HP firmware Ver.2.5.1 and earlier, Aterm WG1800HP4 firmware Ver.1.3.1 and earlier, Aterm WG1800HP3 firmware Ver.1.5.1 and earlier, Aterm WG1200HS2 firmware…

  • CVE-2021-20622MedJan 28, 2021
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors.