CVE-2026-16876CWE-306
An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V
Critical · published September 7, 2026
What it is
An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering with WebGUI messages and sending them to the device via internet.
The record
Technical detail
- CVSS v4.0
- 9.3 · CRITICAL
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N
- EPSS
- Not scored
- Weakness
- CWE-306 · Missing Authentication for Critical Function
- Published
- 2026-09-07T00:48Z
Timeline