CVE-2026-16876
Received
Received - Intake
Authentication Bypass in NEC UNIVERGE IX-R/IX-V WebGUI
Vulnerability report for CVE-2026-16876, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-07
Last updated on: 2026-09-07
Assigner: NEC Corporation
Description
Description
An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| nec | univerge_ix-r | From 1.1 (inc) to 1.3 (inc) |
| nec | univerge_ix-v | From 1.1 (inc) to 1.3 (inc) |
| nec | univerge_ix-r | From 1.4.21 (inc) to 1.4.28 (inc) |
| nec | univerge_ix-v | From 1.4.21 (inc) to 1.4.28 (inc) |
| nec | univerge_ix-r | * |
| nec | univerge_ix-v | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |