CVE-2026-35019Patch

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface. Attackers can forge a valid encrypted session cookie using the shared hardcoded key and bypass authentication checks to obtain full administrative control of the management interface while any legitimate administrator session is active.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-02: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-07-02: 107-02
Signal classification1 categories
Patch
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • Daily CyberSecurity@the_yellow_fall
    Patch

    A NetComm authentication bypass (CVE-2026-35019, CVSS 9.2) uses a hardcoded AES key to forge admin session cookies. Update to firmware R6B032 now. #NetComm #RouterSecurity #CyberSecurity #CVE #PatchNow https://securityonline.info/netcomm-authentication-bypass https://t.co/6vlXlYvgGO

    Post summary

    The post highlights a CVE-2026-35019 authentication bypass in NetComm routers, describes a hard‑coded AES key flaw, and urges users to apply firmware R6B032 for remediation.

    00000443
    12.5K followersView on X

Explore more