PT-2026-51523 · Netcomm · Nf20Mesh

·

CVE-2026-35019

·

Published

2026-03-31

·

Updated

2026-07-02

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NetComm NF20MESH versions prior to R6B032
Description An authentication bypass exists in the web management interface due to a hardcoded AES-256 key used to encrypt session cookies. An unauthenticated attacker can use this shared key to forge a valid encrypted session cookie and gain full administrative control of the interface, provided a legitimate administrator session is active.
Recommendations Update to firmware R6B032.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09207
CVE-2026-35019

Affected Products

Nf20Mesh