Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-35019

Gravedad CVSS v4.0:
CRÍTICA
Tipo:
CWE-321 Uso de claves de cifrado embebidas en el software
Fecha de publicación:
23/06/2026
Última modificación:
23/06/2026

Descripción

*** Pendiente de traducción *** NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface. Attackers can forge a valid encrypted session cookie using the shared hardcoded key and bypass authentication checks to obtain full administrative control of the management interface while any legitimate administrator session is active.