PT-2026-46293 · Neterbit · Nw-431F Router
CVE-2025-67448
·
Published
2026-06-04
·
Updated
2026-06-05
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Neterbit NW-431F Router versions prior to 20241014-IR03
Description
The SMS module contains a stored Cross-Site Scripting (XSS) issue, where the application fails to properly sanitize user input within SMS messages before they are stored and displayed. This allows an attacker to send an SMS containing a malicious payload that executes in the victim's browser when the message is viewed.
Recommendations
Update the firmware to a version later than 20241014-IR03.
As a temporary workaround, restrict access to the SMS module to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nw-431F Router