Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions
Improper Neutralization of Special Elements used in an OS Command vulnerability in NEC Corporation Aterm WG2600HP2, WG2600HP, WG2200HP, WG1800HP2, WG1800HP, WG1400HP, WG600HP, WG300HP, WF300HP, WR9500N, WR9300N, WR8750N, WR8700N, WR8600N, WR8370N, WR8175N and WR8170N all versions allows a attacker to execute an arbitrary OS command with the root privilege, after obtaining a high privilege…
| Vendor | Product | Versions |
|---|---|---|
| NEC Corporation | Aterm WG2600HP2 | all versions |
| NEC Corporation | Aterm WG2600HP | all versions |
| NEC Corporation | Aterm WG2200HP | all versions |
| NEC Corporation | Aterm WG2200HP | all versions |
| NEC Corporation | Aterm WG1800HP2 | all versions |
| NEC Corporation | Aterm WG1800HP | all versions |
| NEC Corporation | Aterm WG1400HP | all versions |
| NEC Corporation | Aterm WG600HP | all versions |
| NEC Corporation | Aterm WG300HP | all versions |
| NEC Corporation | Aterm WF300HP | all versions |
| NEC Corporation | Aterm WR9500N | all versions |
| NEC Corporation | Aterm WR9300N | all versions |
| NEC Corporation | Aterm WR8750N | all versions |
| NEC Corporation | Aterm WR8700N | all versions |
| NEC Corporation | Aterm WR8600N | all versions |
| NEC Corporation | Aterm WR8370N | all versions |
| NEC Corporation | Aterm WR8175N | all versions |
| NEC Corporation | Aterm WR8170N | all versions |
Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.