Beveiligingsadvies

CVE-2026-35019

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-06-23 13:48:49
Laatst bijgewerkt 2026-07-14 20:00:09
Toegewezen door VulnCheck
CVSS-score 9.2
Status PUBLISHED

Beschrijving

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface. Attackers can forge a valid encrypted session cookie using the shared hardcoded key and bypass authentication checks to obtain full administrative control of the management interface while any legitimate administrator session is active.