Cross-site Scripting vulnerability in NEC Corporation...
Critical severity
Unreviewed
Published
Nov 7, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Nov 7, 2025
Published to the GitHub Advisory Database
Nov 7, 2025
Cross-site Scripting vulnerability in NEC Corporation UNIVERGE IX from Ver.9.5 to Ver.10.7, from Ver.10.8.21 to Ver.10.8.36, from Ver.10.9.11 to Ver.10.9.24, from Ver.10.10.21 to Ver.10.10.31, Ver.10.11.6 and UNIVERGE IX-R/IX-V Ver1.3.16, Ver1.3.21 allows an attacker sends specially crafted network packets to the product, arbitrary OS commands may be executed without authentication.
References