CVE-2026-35019

Severity CVSS v4.0:
CRITICAL
Type:
CWE-321 Use of Hard-coded Cryptographic Key
Publication date:
23/06/2026
Last modified:
23/06/2026

Description

NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface. Attackers can forge a valid encrypted session cookie using the shared hardcoded key and bypass authentication checks to obtain full administrative control of the management interface while any legitimate administrator session is active.