CVE-2022-4874 - Netcommwireless Nf20 Firmware, Netcommwireless Nf20mesh Firmware and Netcommwireless Nl1902 Firmware

Critical 7.5

Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a "fake login" to give the request an active session to load the file and not redirect to the login page.

Affected software

Netcommwireless Nf20 Firmware

Netcommwireless Nf20mesh Firmware

Netcommwireless Nl1902 Firmware

Reference links

Get alerted to vulnerabilities in your software

CVE alerts, vulnerability alerts, latest versions and news matched to your software stack.