← Back

Nec

nec

122 CVEs • 348 products

Products (348)

Click to collapse
Toggle
Clusterpro X
clusterpro_x
Asl Ux 4800
asl_ux_4800
Up Ux V
up-ux_v
Ews Ux V
ews-ux_v
Socks 5
socks_5
Goah Intrasv
goah_intrasv
Ix1010
ix1010
Ix1011
ix1011
Ix1020
ix1020
Ix1050
ix1050

CVEs (122)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Nec
1Um8000 Firmware
Jun 17, 2026
Jul 29, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An attacker with knowledge of the modem access number on a NEC UM8000 voicemail system may use SSH tunneling or standard Linux utilities to gain access to the system's LAN port. All versions are affected.
1Nec
4Sl1100 Firmware
Sl2100 FirmwareSv8100 Firmware+1 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cau...Show more
An exploitable privilege escalation vulnerability exists in the WebPro functionality of Aspire-derived NEC PBXes, including all versions of SV8100, SV9100, SL1100 and SL2100 devices. A specially crafted HTTP POST can cause privilege escalation resulting in a higher privileged account, including an undocumented developer level of access.Show less
1Nec
4Sl1100 Firmware
Sl2100 FirmwareSv8100 Firmware+1 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices allow unauthenticated read-only access to voicemails, greetings, and voice response system content t...Show more
Aspire-derived NEC PBXes operating InMail software, including all versions of SV8100, SV9100, SL1100 and SL2100 devices allow unauthenticated read-only access to voicemails, greetings, and voice response system content through a system's WebPro administration interface.Show less
1Nec
4Sl1100 Firmware
Sl2100 FirmwareSv8100 Firmware+1 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password combination to be en...Show more
Aspire-derived NEC PBXes, including the SV8100, SV9100, SL1100 and SL2100 with software releases 7.0 or higher contain the possibility if incorrectly configured to allow a blank username and password combination to be entered as a valid, successfully authenticating account.Show less
1Nec
1Sv9100 Firmware
Jun 17, 2026
Jul 29, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The WebPro interface in NEC SV9100 software releases 7.0 or higher allows unauthenticated remote attackers to reset all existing usernames and passwords to default values via a crafted request.
1Nec
1Sv9100 Firmware
Jun 17, 2026
Jul 29, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password, aka a Static Credential Vulnerability. The vu...Show more
Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password, aka a Static Credential Vulnerability. The vulnerability is due to an undocumented user account with manufacturer privilege level. An attacker could exploit this vulnerability by using this account to remotely log into an affected device. A successful exploit could allow the attacker to log into the device with manufacturer level access. This vulnerability affects SV9100 PBXes that are running software release 6.0 or higher. This vulnerability does not affect SV9100 software releases prior to 6.0.Show less
1Nec
1Esmpro Manager
Jun 17, 2026
Jul 22, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NEC ESMPRO Manager 6.42. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RMI service. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-10007.Show less
21Asus
BroadcomCanon+18 more
2175020 Z4a69a
5030 M2u92b5030 Z4a70a+214 more
Jun 17, 2026
Jun 8, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscriptio...Show more
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.Show less
1Nec
1Aterm Wg2600hs Firmware
Jun 17, 2026
Feb 21, 2020
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
Aterm WG2600HS firmware Ver1.3.2 and earlier allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via unspecified vectors.
1Nec
1Aterm Wg2600hs Firmware
Jun 17, 2026
Feb 21, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.3.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
1Nec
3Aterm Wf1200c Firmware
Aterm Wg1200cr FirmwareAterm Wg2600hs Firmware
Jun 17, 2026
Feb 21, 2020
N/A· v4
8.0 HIGH· v3
7.7 HIGH· v2
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an authenticated attacker on the same network segment to execu...Show more
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an authenticated attacker on the same network segment to execute arbitrary OS commands with root privileges via management screen.Show less
1Nec
3Aterm Wf1200c Firmware
Aterm Wg1200cr FirmwareAterm Wg2600hs Firmware
Jun 17, 2026
Feb 21, 2020
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an attacker on the same network segment to execute arbitrary O...Show more
Aterm series (Aterm WF1200C firmware Ver1.2.1 and earlier, Aterm WG1200CR firmware Ver1.2.1 and earlier, Aterm WG2600HS firmware Ver1.3.2 and earlier) allows an attacker on the same network segment to execute arbitrary OS commands with root privileges via UPnP function.Show less
1Nec
2Aterm Wf1200cr Firmware
Aterm Wg1200cr Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows an attacker on the same network segment to execute arbitrary OS commands via SOAP inte...Show more
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows an attacker on the same network segment to execute arbitrary OS commands via SOAP interface of UPnP.Show less
1Nec
2Aterm Wf1200cr Firmware
Aterm Wg1200cr Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.
1Nec
2Aterm Wf1200cr Firmware
Aterm Wg1200cr Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting vulnerability in Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to inject arbitrary web...Show more
Cross-site scripting vulnerability in Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allows authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
1Nec
2Aterm Wf1200cr Firmware
Aterm Wg1200cr Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allow an attacker on the same network segment to obtain information registered on the device...Show more
Aterm WF1200CR and Aterm WG1200CR (Aterm WF1200CR firmware Ver1.1.1 and earlier, Aterm WG1200CR firmware Ver1.0.1 and earlier) allow an attacker on the same network segment to obtain information registered on the device via unspecified vectors.Show less
1Nec
1Aterm Hc100rc Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via tools_system.cgi date parameter, time parameter, and offset parameter.
1Nec
1Aterm Hc100rc Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date parameter, time parameter, and offset parameter.
1Nec
1Aterm Hc100rc Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via tools_firmware.cgi date parameter, time parameter, and offset parameter.
1Nec
1Aterm Hc100rc Firmware
Nov 21, 2024
Jan 9, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via import.cgi encKey parameter.