CVE-2026-6059: Nec Platforms, Ltd Aterm 19000t12be
Medium severity, CVSS 4.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.
Affected products
- Nec Platforms, Ltd Aterm 19000t12be: before 1.1.0 (fixed in 1.1.0)
- Nec Platforms, Ltd Aterm GX621A1: before 3.2.2 (fixed in 3.2.2)
- Nec Platforms, Ltd Aterm SH621A1: before 3.2.2 (fixed in 3.2.2)
- Nec Platforms, Ltd Aterm WX11000T12: before 1.4.0 (fixed in 1.4.0)
- Nec Platforms, Ltd Aterm WX1800HP: before 3.2.2 (fixed in 3.2.2)
- Nec Platforms, Ltd Aterm WX3000HP2: before 1.3.2 (fixed in 1.3.2)
- Nec Platforms, Ltd Aterm WX4200D5: before 1.3.5 (fixed in 1.3.5)
- Nec Platforms, Ltd Aterm WX5400HP: before 2.1.0 (fixed in 2.1.0)
- Nec Platforms, Ltd Aterm WX7800T8: before 1.5.1 (fixed in 1.5.1)
Published 2026-05-25. Last modified 2026-07-23.