CVE-2026-4619 is a Path Traversal vulnerability (CWE-22) affecting NEC Platforms, Ltd. Aterm Series devices, allowing an attacker to write over arbitrary files on the system. Rated Medium severity (CVSSv4 6.0), successful exploitation requires high privileges and high attack complexity, but could result in significant integrity and availability impacts through arbitrary file overwrites. There is currently no public exploit code available, it is not listed in CISA's KEV catalog, and has seen minimal community discussion, with an extremely low EPSS score indicating a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.3CPE matchmatch criteria | cpe:2.3:o:nec:aterm_wx3600hp_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.