PT-2026-51523 · Netcomm · Nf20Mesh
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NetComm NF20MESH versions prior to R6B032
Description
An authentication bypass exists in the web management interface due to a hardcoded AES-256 key used to encrypt session cookies. An unauthenticated attacker can use this shared key to forge a valid encrypted session cookie and gain full administrative control of the interface, provided a legitimate administrator session is active.
Recommendations
Update to firmware R6B032.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nf20Mesh