Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

NEC Corporation

First CVE: Dec 12, 1995Active for: 31 yearsTotal CVEs: 122
43.2
VTI Score
High

NEC Corporation's vulnerability footprint spans a broad portfolio of enterprise clustering systems and consumer networking devices, including its ExpressCluster middleware and ATERM wireless router and access-point lines, positioning it prominently in both data-center and home-network deployments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the convergence of privileged middleware roles and embedded firmware attack surfaces across its product range. The exposure recurs through weakness classes including OS command injection, improper authentication, and classic buffer overflows—flaws endemic to command-line interfaces and network protocol parsing in systems that frequently operate with high trust and minimal user isolation. Defenders should prioritize updates to internet-reachable ATERM devices and validate authentication controls in ExpressCluster deployments within their infrastructure. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
122
Total CVEs
More Total CVEs than 99% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by NEC Corporation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 12, 1995
30 years ago
Most Recent CVE
Mar 27, 2026
119 days ago

Products(348 total)

Top CVEs

Signals from CVEs in this vendor scope (122 CVEs).

122 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-17408HIGH
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vul
Sep 10, 20207.558NONO
CVE-1999-0043CRITICAL
Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others.
Dec 4, 19969.855NONO
CVE-1999-0009HIGH
Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases.
Apr 8, 199810.054NOYES
CVE-2018-11741CRITICAL
NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs.
Dec 26, 20189.852NOYES
CVE-2018-11742CRITICAL
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
Dec 26, 20189.850NOYES
CVE-1999-0208HIGH
rpc.ypupdated (NIS) allows remote users to execute arbitrary commands.
Dec 12, 199510.041NOYES
CVE-2026-4620CRITICAL
OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.
Mar 27, 20269.837NONO
CVE-2026-4622CRITICAL
OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.
Mar 27, 20269.836NONO
CVE-2026-4619CRITICAL
Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network.
Mar 27, 20269.836NONO
CVE-2019-20025CRITICAL
Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password, aka a
Jul 29, 20209.833NONO
View all 122 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products122 CVEs
20%
51%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (3.3%)
Network88 (72.1%)
Unknown24 (19.7%)
Physical0 (0.0%)
Adjacent Network6 (4.9%)
Attack Complexity
Low95 (77.9%)
High3 (2.5%)
Unknown24 (19.7%)
User Interaction
None93 (76.2%)
Unknown24 (19.7%)
Required5 (4.1%)
Privileges Required
Low16 (13.1%)
High24 (19.7%)
None58 (47.5%)
Unknown24 (19.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (122 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
4.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by NEC Corporation.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by NEC Corporation — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For NEC Corporation's Products

View all 4 CNAs →

Top CWEs