A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.
History

Tue, 26 May 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 May 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Necplatforms
Necplatforms aterm 19000t12be
Necplatforms aterm Gx621a1
Necplatforms aterm Sh621a1
Necplatforms aterm Wx11000t12
Necplatforms aterm Wx1800hp
Necplatforms aterm Wx3000hp2
Necplatforms aterm Wx4200d5
Necplatforms aterm Wx5400hp
Necplatforms aterm Wx7800t8
Vendors & Products Necplatforms
Necplatforms aterm 19000t12be
Necplatforms aterm Gx621a1
Necplatforms aterm Sh621a1
Necplatforms aterm Wx11000t12
Necplatforms aterm Wx1800hp
Necplatforms aterm Wx3000hp2
Necplatforms aterm Wx4200d5
Necplatforms aterm Wx5400hp
Necplatforms aterm Wx7800t8

Mon, 25 May 2026 05:15:00 +0000

Type Values Removed Values Added
Title Cross‑Site Scripting Allowing Arbitrary Browser Script Execution in NEC Aterm Management Interface

Mon, 25 May 2026 03:30:00 +0000

Type Values Removed Values Added
Description A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: NEC

Published: 2026-05-25T02:22:29.809Z

Updated: 2026-05-26T14:44:05.754Z

Reserved: 2026-04-10T01:20:30.411Z

Link: CVE-2026-6059

cve-icon Vulnrichment

Updated: 2026-05-26T14:44:00.184Z

cve-icon NVD

Status : Received

Published: 2026-05-25T04:16:25.030

Modified: 2026-05-25T04:16:25.030

Link: CVE-2026-6059

cve-icon Redhat

No data.