NEC Corporation's vulnerability footprint spans a broad portfolio of enterprise clustering systems and consumer networking devices, including its ExpressCluster middleware and ATERM wireless router and access-point lines, positioning it prominently in both data-center and home-network deployments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the convergence of privileged middleware roles and embedded firmware attack surfaces across its product range. The exposure recurs through weakness classes including OS command injection, improper authentication, and classic buffer overflows—flaws endemic to command-line interfaces and network protocol parsing in systems that frequently operate with high trust and minimal user isolation. Defenders should prioritize updates to internet-reachable ATERM devices and validate authentication controls in ExpressCluster deployments within their infrastructure. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by NEC Corporation over time
Signals from CVEs in this vendor scope (122 CVEs).
122 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-17408HIGH This vulnerability allows remote attackers to disclose sensitive information on affected installations of NEC ExpressCluster 4.1. Authentication is not required to exploit this vul | Sep 10, 2020 | 7.5 | 58 | NO | NO |
CVE-1999-0043CRITICAL Command execution via shell metachars in INN daemon (innd) 1.5 using "newgroup" and "rmgroup" control messages, and others. | Dec 4, 1996 | 9.8 | 55 | NO | NO |
CVE-1999-0009HIGH Inverse query buffer overflow in BIND 4.9 and BIND 8 Releases. | Apr 8, 1998 | 10.0 | 54 | NO | YES |
CVE-2018-11741CRITICAL NEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via Home.htm?sessionId=#####&GOTO(8) URIs. | Dec 26, 2018 | 9.8 | 52 | NO | YES |
CVE-2018-11742CRITICAL NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI. | Dec 26, 2018 | 9.8 | 50 | NO | YES |
CVE-1999-0208HIGH rpc.ypupdated (NIS) allows remote users to execute arbitrary commands. | Dec 12, 1995 | 10.0 | 41 | NO | YES |
CVE-2026-4620CRITICAL OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network. | Mar 27, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-4622CRITICAL OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network. | Mar 27, 2026 | 9.8 | 36 | NO | NO |
CVE-2026-4619CRITICAL Path Traversal vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to wtite over any file via network. | Mar 27, 2026 | 9.8 | 36 | NO | NO |
CVE-2019-20025CRITICAL Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password, aka a | Jul 29, 2020 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (122 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by NEC Corporation.
Media articles that mention a CVE ID that affects a product developed by NEC Corporation — matched by CVE ID, not by vendor name.