PT-2023-1320 · Netcomm · Netcomm Nf20+2
Published
2023-01-11
·
Updated
2023-01-19
·
CVE-2022-4874
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Netcomm NF20 versions
Netcomm NF20MESH versions
Netcomm NL1902 versions
Description
The issue is related to an authentication bypass in the Netcomm router models. This allows an unauthenticated user to access content. The application checks for specific characters in the URL, such as
.css or .png, and performs a "fake login" to give the request an active session, allowing the file to be loaded without redirecting to the login page.Recommendations
For Netcomm NF20, consider disabling access to static content until a patch is available.
For Netcomm NF20MESH, restrict access to the application's URL checking functionality to minimize the risk of exploitation.
For Netcomm NL1902, avoid using the "fake login" mechanism for serving static content until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Improper Authentication
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Netcomm Nf20
Netcomm Nf20Mesh
Netcomm Nl1902