CVE-2026-4620: Nec Aterm WX1500HP Firmware

Critical severity, CVSS 9.8. EPSS: 1.2% chance of exploitation in the next 30 days.

OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.

Affected products

  • Nec Aterm WX1500HP Firmware: before 1.4.2 (fixed in 1.4.2)
  • Nec Aterm WX3600HP Firmware: before 1.5.3 (fixed in 1.5.3)

Published 2026-03-27. Last modified 2026-06-17.