Junglewise Threat Intelligence

CVE-2025-67446: Neterbit NW-431F authentication bypass via predictable cookie

CVE-2025-67446 · Severity: critical · CVSS 9.8 · Published 2026-06-04

Technologies: Neterbit NW-431F Router. Vendors: Neterbit.

Executive brief

A security vulnerability exists in the Neterbit NW-431F, a 4G LTE desktop router used for providing internet connectivity to homes and offices. The device fails to properly verify user identity, allowing anyone to gain full administrative control by simply changing a piece of data in their web browser. An attacker who takes over the router can monitor network traffic, change security settings, or disrupt internet service for all connected users.

Technical details

An improper authentication vulnerability exists in the web management interface of the Neterbit NW-431F router. The application relies on a weak and predictable cookie-based authentication mechanism where the 'username' cookie value is used to determine authorization levels. By manually modifying the HTTP request to include a cookie such as 'username=admin', a remote, unauthenticated attacker can bypass the login schema. This allows for full access to administrative functionalities and configuration pages. As of the advisory date, no patched firmware version has been confirmed.

Affected products

  • Neterbit NW-431F Router 20241014-IR03 and earlier

Timeline

  • 2026-06-04: disclosed: CVE published to the NVD dataset

References

Related threats