LiveActive security incident?Get immediate response
CVE Record

CVE-2019-20025: Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device...

Certain builds of NEC SV9100 software could allow an unauthenticated, remote attacker to log into a device running an affected release with a hardcoded username and password, aka a Static Credential Vulnerability. The vulnerability is due to an undocumented user account with manufacturer privilege level. An attacker could exploit this vulnerability by using this account to remotely log into an affected device. A successful exploit could allow the attacker to log into the device with manufacturer level access. This vulnerability affects SV9100 PBXes that are running software release 6.0 or higher. This vulnerability does not affect SV9100 software releases prior to 6.0.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

CVE-2019-20025 describes a hardcoded credential issue in certain NEC SV9100 PBX software builds. A remote unauthenticated attacker could log in with manufacturer-level access on affected devices. This is business-relevant because PBX compromise can affect voice services, call routing, configuration integrity, and potentially sensitive communications metadata.

Executive priority

Treat this as a high-priority telephony infrastructure exposure if SV9100 systems are present. The impact is privileged remote access, but the exact affected build list and fix status are incomplete in the provided sources, so prioritize inventory, exposure reduction, and vendor confirmation.

Technical view

The CVE reports an undocumented account with manufacturer privilege level in certain NEC SV9100 software builds. Affected systems are SV9100 PBXes running software release 6.0 or higher; releases before 6.0 are stated as unaffected. No CVSS, CWE, patch version, or precise build list is provided in the source bundle.

Likely exposure

Exposure is limited to NEC SV9100 PBX systems on software release 6.0 or later, especially where remote login or management access is reachable from untrusted networks. The sources say “certain builds,” so exact vulnerable build confirmation requires vendor guidance or local validation.

Exploitation context

The source bundle does not show CISA KEV listing or other evidence of active exploitation. The vulnerability is remotely reachable in principle because the described attack path is remote login using a static credential, but no exploit campaign or weaponized exploit status is cited.

Researcher notes

The CVE description is specific about SV9100 release 6.0 or higher and manufacturer-level access, but the bundle lacks CVSS, CWE, vendor patch data, and exact affected builds. Do not assume all 6.0+ deployments are vulnerable without confirming “certain builds” through NEC or authorized support information.

Mitigation direction

  • Check NEC or support-channel guidance for affected builds and fixed releases.
  • Restrict PBX management access to trusted administrative networks only.
  • Remove internet exposure for SV9100 login and management services.
  • Place PBX administration behind VPN, firewall ACLs, or equivalent controls.
  • Review accounts and configuration for unauthorized manufacturer-level changes.
  • Increase monitoring for unusual PBX login and administration activity.

Validation and detection

  • Inventory all NEC SV9100 PBX systems and software release versions.
  • Flag SV9100 systems running release 6.0 or higher for vendor confirmation.
  • Confirm whether remote login interfaces are reachable from untrusted networks.
  • Review PBX logs for unexpected privileged or manufacturer-level access.
  • Verify firewall rules restrict PBX management to approved administrators.
  • Document vendor patch or mitigation status for each affected PBX.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Credential and access behavior lookup

The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2019-20025 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/an/an/aListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.