CVE-2026-35018
HIGHNetComm NF20MESH < R6B032 Authenticated RCE via OS Command Injection
Title source: cnaDescription
NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands as root by injecting shell metacharacters into the username JSON parameter processed by the dalStorage_addUserAccount function. Attackers can exploit the unsafe concatenation of user-supplied input into a shell command string passed to rut_doSystemAction without sanitization to achieve full root-level command execution on the underlying operating system.
References (4)
Core 4
Core References
Technical Description technical-description
https://signal11.io/advisories/netcomm-nf20-mesh-remote-code-execution
Patch release-notes
patch
https://support.netcommwireless.com/api/Media/Firmware/4407c21d-e990-49a4-9754-b72475f20c76?Product=NF20MESH%20Release%20Notes.pdf
Product product
https://support.netcommwireless.com/products/nf20mesh#Firmware
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/netcomm-nf20mesh-r6b032-authenticated-rce-via-os-command-injection
Scores
CVSS v3
8.8
EPSS
0.0066
EPSS Percentile
48.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
CWE
CWE-78
Status
published
Products (1)
NetComm Wireless Pty Ltd/NF20MESH
< R6B032
Published
Jun 23, 2026
Tracked Since
Jun 23, 2026