Authenticated bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows unauthenticated user to get access to content.
Published Jan 11, 2023
7.5
HIGHCVSS 3.1
EPSS 11.01%
Description
Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a "fake login" to give the request an active session to load the file and not redirect to the login page.
Affected products
-
- Version R6B025StatusaffectedConstraints-
- Version
-
- Version R6B025StatusaffectedConstraints-
- Version
-
- Version R6B025StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
Configuration 1
- < r6b025
Running on/with
- n/a
Configuration 2
- < r6b025
Running on/with
- n/a
Configuration 3
- < r6b025
Running on/with
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-52134 Advisory
- https://github.com/scarvell/advisories/blob/main/2022_netcomm_nf20mesh_unauth_rce.md ExploitThird Party Advisory
- https://www.kb.cert.org/vuls/id/986018
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-52134 | Advisory | |
| https://github.com/scarvell/advisories/blob/main/2022_netcomm_nf20mesh_unauth_rce.md | ExploitThird Party Advisory | |
| https://www.kb.cert.org/vuls/id/986018 |
Change history (0)
No recorded changes yet.