CVE-2026-6059 Details
Description
A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.
A cross-site scripting vulnerability has been identified in the NEC Aterm series routers. This issue allows arbitrary scripts to be executed in the web browser of a user accessing the web management interface over an adjacent network. The vulnerability affects several models, including the WX1800HP, WX5400HP, WX7800T8, WX11000T12, WX3000HP2, WX4200D5, GX621A1, SH621A1, and 19000T12BE, all prior to their respective latest versions.
Users are advised to update their devices to the latest version. For more information, please visit the NEC Aterm support page (available only in Japanese).
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 25, 2026CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jpn.nec.com/security-info/secinfo/nv26-002_en.html | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NEC Aterm WX1800HP | < 3.2.2 (semver) |
CPE
Remediation
| |
| NEC Aterm WX5400HP | < 2.1.0 (semver) |
CPE
Remediation
| |
| NEC Aterm WX7800T8 | < 1.5.1 (semver) |
CPE
Remediation
| |
| NEC Aterm WX11000T12 | < 1.4.0 (semver) |
CPE
Remediation
| |
| NEC Aterm WX3000HP2 | < 1.3.2 (semver) |
CPE
Remediation
| |
| NEC Aterm WX4200D5 | < 1.3.5 (semver) |
CPE
Remediation
| |
| NEC Aterm GX621A1 | < 3.2.2 (semver) |
CPE
Remediation
| |
| NEC Aterm SH621A1 | < 3.2.2 (semver) |
CPE
Remediation
| |
| NEC Aterm 19000T12BE | < 1.1.0 (semver) |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 25, 2026 | New CVE Received | [email protected] |
Volerion