CVE-2026-8652: OS Command Injection
An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjacent network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the web console if it is not required to prevent remote administrative access that could be used to execute arbitrary OS commands.
Aterm web console web_console_enabled = false - Compensating control
Restrict access to the Aterm web console to trusted IP addresses and/or require access via a VPN; enforce firewall rules to limit management interface access to authorized hosts only.
- Compensating control
Place the product's management/web console on an isolated management network separated from adjacent networks to reduce the risk of lateral access and OS command execution.
- Operational
Monitor administrative access logs for suspicious activity; if compromise is suspected, revoke or rotate administrative credentials and session tokens immediately.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8652?
CVE-2026-8652 has a risk score of 52, indicating a medium severity level.
How do I fix CVE-2026-8652?
To fix CVE-2026-8652, ensure that all access to the web console is restricted and consider applying any available patches from the vendor.
What software is affected by CVE-2026-8652?
CVE-2026-8652 affects the Aterm software.
What kind of vulnerability is CVE-2026-8652?
CVE-2026-8652 is classified as an OS Command Injection vulnerability.
What are the potential consequences of CVE-2026-8652?
If exploited, CVE-2026-8652 can allow an attacker with administrator access to execute arbitrary OS commands, posing significant security risks.