NEC patches a flaw that runs CLI commands with no authentication on UNIVERGE IX routers
NEC fixes CVE-2026-16876, a critical missing-authentication flaw (CVSS 9.4) in the WebGUI of UNIVERGE IX-R and IX-V enterprise routers: a forged message bypasses login and runs arbitrary CLI commands. Apply the firmware update, or disable the WebGUI if it is reachable from the internet.