Executive brief
The Neterbit NW-431F, a 4G desktop router used for home and office internet connectivity, contains a security flaw in its SMS management module. An attacker can send a specially crafted SMS message to the router that, when viewed by an administrator through the web management interface, executes malicious code in their browser. This could allow an attacker to steal login session cookies or perform unauthorized actions on the router.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in the SMS module of the Neterbit NW-431F router. The vulnerability is caused by a failure to properly sanitize user-supplied input within SMS messages before they are stored and rendered in the web-based management console. An unauthenticated remote attacker can exploit this by sending an SMS containing a malicious JavaScript payload. When an authenticated user views the SMS inbox via the router's web interface, the payload executes in the context of their browser session, potentially leading to session hijacking via cookie theft or unauthorized configuration changes. As of the advisory date, a fixed version has not been identified.
Affected products
- Neterbit NW-431F Router 20241014-IR03 and earlier
Timeline
- 2026-06-04: advisory: NVD publication date
- 2026-06-04: disclosed: Public disclosure of vulnerability and PoC