CVE-2026-16876 — NEC UNIVERGE IX-R/IX-V Authentication Bypass Enables Remote CLI Access

CVE & Vulnerabilities · September 9, 2026

CVE & Vulnerabilities·nvd.nist.gov

A newly disclosed flaw in the web management interface of NEC's UNIVERGE IX-R and IX-V router series lets an attacker skip authentication entirely. By manipulating messages sent to the device's WebGUI over the internet, an attacker could gain the ability to execute arbitrary commands on the underlying command-line interface. Tracked as CVE-2026-16876, it's a reminder of the risk that comes with exposing router management interfaces directly to the internet.

// source: nvd.nist.gov ↗

Back to Blog