CVE-2026-35019

HIGH

NetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass

Title source: cna
STIX 2.1

Description

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface. Attackers can forge a valid encrypted session cookie using the shared hardcoded key and bypass authentication checks to obtain full administrative control of the management interface while any legitimate administrator session is active.

Scores

CVSS v3 8.1
EPSS 0.0047
EPSS Percentile 38.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-321
Status published
Products (1)
NetComm Wireless Pty Ltd/NF20MESH < R6B032
Published Jun 23, 2026
Tracked Since Jun 23, 2026