CVE-2026-4620: OS Command Injection
Published Mar 27, 2026
·Updated
OS Command Injection vulnerability in NEC Platforms, Ltd. Aterm Series allows a attacker to execute arbitrary OS commands via network.
Affected Software
5 affected components
NEC Platforms Aterm Series
All of the following
NEC Aterm Wx3600hp Firmware<1.5.3
NEC Aterm WX3600HP
All of the following
NEC Aterm Wx1500hp Firmware<1.4.2
NEC Aterm WX1500HP
Event History
Mar 27, 2026
CVE Published
via MITRE·11:53 AM
Data Sourced
via MITRE·11:53 AM
DescriptionWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-4620?
CVE-2026-4620 is classified as a high-severity OS Command Injection vulnerability.
2
How do I fix CVE-2026-4620?
To mitigate CVE-2026-4620, ensure that your NEC Platforms Aterm Series devices are updated to the latest firmware that addresses this vulnerability.
3
What impact does CVE-2026-4620 have on NEC Platforms Aterm Series devices?
CVE-2026-4620 allows attackers to execute arbitrary OS commands, potentially compromising the device and the network.
4
Who is affected by CVE-2026-4620?
Any user of NEC Platforms Aterm Series devices is at risk if they have not applied necessary security updates.
5
What can attackers do with CVE-2026-4620?
Attackers can exploit CVE-2026-4620 to execute malicious OS commands remotely, gaining unauthorized access to the system.