Executive brief
A security vulnerability has been identified in the Neterbit NW-431F, a 4G LTE desktop router used for home and office internet connectivity. An attacker can remotely access a specific management page to view sensitive information, such as private SMS messages, or execute unauthorized commands. This could lead to a complete compromise of the device, data theft, or disruption of internet services.
Technical details
A vulnerability in the Neterbit NW-431F router (firmware vNW-431F-20241014-IR03) stems from a lack of authentication and authorization on the 'at_command.asp' management interface. A remote, unauthenticated attacker can access this page over the network and submit crafted AT commands. This allows for sensitive information disclosure (such as reading SMS messages via AT+CMGL) and potentially arbitrary code execution or device reconfiguration. As of the advisory date, no official patch has been confirmed by the vendor.
Affected products
- Neterbit NW-431F Router vNW-431F-20241014-IR03
Timeline
- 2026-06-04: disclosed: CVE published to NVD dataset