Executive brief
A security vulnerability exists in the Neterbit NW-431F, a 4G LTE desktop router used for providing internet connectivity to homes and offices. The device fails to properly verify user identity, allowing anyone to gain full administrative control by simply changing a piece of data in their web browser. An attacker who takes over the router can monitor network traffic, change security settings, or disrupt internet service for all connected users.
Technical details
An improper authentication vulnerability exists in the web management interface of the Neterbit NW-431F router. The application relies on a weak and predictable cookie-based authentication mechanism where the 'username' cookie value is used to determine authorization levels. By manually modifying the HTTP request to include a cookie such as 'username=admin', a remote, unauthenticated attacker can bypass the login schema. This allows for full access to administrative functionalities and configuration pages. As of the advisory date, no patched firmware version has been confirmed.
Affected products
- Neterbit NW-431F Router 20241014-IR03 and earlier
Timeline
- 2026-06-04: disclosed: CVE published to the NVD dataset