Junglewise Threat Intelligence

CVE-2026-35018: NetComm NF20MESH command injection in dalStorage_addUserAccount

CVE-2026-35018 · Severity: high · CVSS 8.8 · Published 2026-06-23

Executive brief

NetComm NF20MESH routers, commonly used for home and small office internet connectivity, contain a security flaw that allows an authorized user to take full control of the device. By submitting a specially crafted username during account setup, an attacker can bypass security restrictions to run unauthorized commands. This could lead to the theft of sensitive configuration data, interception of network traffic, or a complete shutdown of the internet service.

Technical details

An OS command injection vulnerability exists in the dalStorage_addUserAccount function of NetComm NF20MESH routers. The vulnerability is caused by the unsafe concatenation of the 'username' JSON parameter into a shell command string (specifically a 'mkdir' command) which is then executed via rut_doSystemAction without proper sanitization. An authenticated attacker with low privileges can exploit this by injecting shell metacharacters into the username field. Successful exploitation grants full root-level access to the underlying Linux operating system. The issue is resolved in firmware version R6B032.

Affected products

  • NetComm NF20MESH R6B031 and earlier

Timeline

  • 2026-03-31: other: Vulnerability identified by Signal 11
  • 2026-04-01: other: Initial vendor notification
  • 2026-05-26: patched: Vendor provided patched version for testing
  • 2026-06-18: other: Vendor advised fix was publicly released
  • 2026-06-22: advisory: Signal 11 advisory published
  • 2026-06-23: disclosed: NVD publication date

References

Related threats