Junglewise Threat Intelligence

CVE-2025-69755: Neterbit NW-431F auth bypass in at_command.asp

CVE-2025-69755 · Severity: high · CVSS 8.2 · Published 2026-06-04

Technologies: Neterbit NW-431F Router. Vendors: Neterbit.

Executive brief

A security vulnerability has been identified in the Neterbit NW-431F, a 4G LTE desktop router used for home and office internet connectivity. An attacker can remotely access a specific management page to view sensitive information, such as private SMS messages, or execute unauthorized commands. This could lead to a complete compromise of the device, data theft, or disruption of internet services.

Technical details

A vulnerability in the Neterbit NW-431F router (firmware vNW-431F-20241014-IR03) stems from a lack of authentication and authorization on the 'at_command.asp' management interface. A remote, unauthenticated attacker can access this page over the network and submit crafted AT commands. This allows for sensitive information disclosure (such as reading SMS messages via AT+CMGL) and potentially arbitrary code execution or device reconfiguration. As of the advisory date, no official patch has been confirmed by the vendor.

Affected products

  • Neterbit NW-431F Router vNW-431F-20241014-IR03

Timeline

  • 2026-06-04: disclosed: CVE published to NVD dataset

References

Related threats