CVE-2026-35019
HIGHNetComm NF20MESH < R6B032 Hardcoded AES Key Authentication Bypass
Title source: cnaDescription
NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface. Attackers can forge a valid encrypted session cookie using the shared hardcoded key and bypass authentication checks to obtain full administrative control of the management interface while any legitimate administrator session is active.
References (4)
Core 4
Core References
Technical Description technical-description
https://signal11.io/advisories/netcomm-nf20-mesh-authentication-bypass
Patch release-notes
patch
https://support.netcommwireless.com/api/Media/Firmware/4407c21d-e990-49a4-9754-b72475f20c76?Product=NF20MESH%20Release%20Notes.pdf
Product product
https://support.netcommwireless.com/products/nf20mesh#Firmware
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/netcomm-nf20mesh-r6b032-hardcoded-aes-key-authentication-bypass
Scores
CVSS v3
8.1
EPSS
0.0047
EPSS Percentile
38.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-321
Status
published
Products (1)
NetComm Wireless Pty Ltd/NF20MESH
< R6B032
Published
Jun 23, 2026
Tracked Since
Jun 23, 2026