CVE Database
/

CVE-2022-4874

Back to search

CVE-2022-4874

Published: Jan 11, 2023

Modified: Nov 4, 2025

PUBLISHED

Description

Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a "fake login" to give the request an active session to load the file and not redirect to the login page.

VendorProductVersions

Netcomm

NF20

affected
R6B025

Netcomm

NF20MESH

affected
R6B025

Netcomm

NL1902

affected
R6B025

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now