Aterm is a Japanese networking equipment manufacturer with a focused product portfolio centered on wireless routers and related networking appliances, particularly its WG2600HP line and variants. Vulnerabilities affecting this vendor recur through web-interface weaknesses including cross-site request forgery, cross-site scripting, and missing authentication for critical functions, reflecting the attack surface inherent to embedded web-management interfaces. The vendor's disclosures tend toward moderate severity outcomes and have shown a moderate tendency toward both confirmed in-the-wild exploitation and public exploit availability. Live exploitation activity, severity distribution, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Aterm over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2014-8361CRITICAL The miniigd SOAP service in Realtek SDK allows remote attackers to execute arbitrary code via a crafted NewInternalClient request, as exploited in the wild through 2023. | May 1, 2015 | 9.8 | 98 | YES | YES |
CVE-2016-1168HIGH Cross-site request forgery (CSRF) vulnerability on NEC Aterm WF800HP devices with firmware 1.0.17 and earlier allows remote attackers to hijack the authentication of arbitrary user | Apr 1, 2016 | 8.8 | 29 | NO | NO |
CVE-2016-1167HIGH Cross-site request forgery (CSRF) vulnerability on NEC Aterm WG300HP devices allows remote attackers to hijack the authentication of arbitrary users. | Apr 1, 2016 | 8.8 | 28 | NO | NO |
CVE-2017-12575HIGH An issue was discovered on the NEC Aterm WG2600HP2 1.0.2. The router has a set of web service APIs for access to and setup of the configuration. Some APIs don't require authenticat | Aug 24, 2018 | 7.5 | 26 | NO | NO |
CVE-2021-20621HIGH Cross-site request forgery (CSRF) vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to hijack | Jan 28, 2021 | 8.8 | 25 | NO | NO |
CVE-2003-0024HIGH The menuBar feature in aterm 0.42 allows attackers to modify menu options and execute arbitrary commands via a certain character escape sequence that inserts the commands into the | Mar 3, 2003 | 7.5 | 22 | NO | NO |
CVE-2021-20710MEDIUM Cross-site scripting vulnerability in Aterm WG2600HS firmware Ver1.5.1 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors. | Apr 26, 2021 | 6.1 | 20 | NO | NO |
CVE-2003-0067HIGH The aterm terminal emulator 0.42 allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's termi | Mar 18, 2003 | 7.5 | 20 | NO | NO |
CVE-2021-20622MEDIUM Cross-site scripting vulnerability in Aterm WG2600HP firmware Ver1.0.2 and earlier, and Aterm WG2600HP2 firmware Ver1.0.2 and earlier allows remote attackers to inject an arbitrary | Jan 28, 2021 | 6.1 | 19 | NO | NO |
CVE-2021-20620MEDIUM Cross-site scripting vulnerability in Aterm WF800HP firmware Ver1.0.9 and earlier allows remote attackers to inject an arbitrary script via unspecified vectors. | Jan 28, 2021 | 6.1 | 19 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Aterm.
Media articles that mention a CVE ID that affects a product developed by Aterm — matched by CVE ID, not by vendor name.