Junglewise Threat Intelligence

CVE-2026-35019: NetComm NF20MESH authentication bypass via hardcoded AES key

CVE-2026-35019 · Severity: high · CVSS 8.1 · Published 2026-06-23

Executive brief

NetComm NF20MESH routers, commonly used for home and small office internet connectivity, contain a security flaw in their web management interface. An attacker can bypass the login screen to gain full administrative control of the device if a legitimate administrator is currently logged in. This could allow an unauthorized person to change network settings, intercept traffic, or disable security features.

Technical details

An authentication bypass vulnerability exists in the session handling logic of NetComm NF20MESH routers. The device uses a hardcoded AES-256 key ('TWgj@config@EncodeDecode') to encrypt and decrypt session cookies. Because the device validates authentication by checking for any active session and ensuring the provided cookie can be decrypted with this static key, an unauthenticated attacker can forge a valid session cookie. Successful exploitation requires a legitimate administrator to have an active session at the time of the attack. This allows the attacker to obtain full administrative control via the web management interface. The issue is resolved in firmware version R6B032.

Affected products

  • NetComm NF20MESH R6B031 and earlier

Timeline

  • 2026-03-31: other: Vulnerability identified by Signal 11
  • 2026-04-01: other: Initial vendor notification
  • 2026-05-26: patched: Vendor provided patched version for testing
  • 2026-06-18: other: Vendor advised fix was publicly released
  • 2026-06-22: advisory: Signal 11 advisory published
  • 2026-06-23: disclosed: CVE published and NVD entry created

References

Related threats