PT-2026-46293 · Neterbit · Nw-431F Router

CVE-2025-67448

·

Published

2026-06-04

·

Updated

2026-06-05

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Neterbit NW-431F Router versions prior to 20241014-IR03
Description The SMS module contains a stored Cross-Site Scripting (XSS) issue, where the application fails to properly sanitize user input within SMS messages before they are stored and displayed. This allows an attacker to send an SMS containing a malicious payload that executes in the victim's browser when the message is viewed.
Recommendations Update the firmware to a version later than 20241014-IR03. As a temporary workaround, restrict access to the SMS module to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-67448

Affected Products

Nw-431F Router