CVE-2026-35019
NetComm Wireless Pty Ltd NF20MESH
NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows unauthenticated attackers to gain administrative access by exploiting a hardcoded AES-256 key used to encrypt session cookies for the web management interface. Attackers can forge a valid encrypted session cookie using the shared hardcoded key and bypass authentication checks to obtain full administrative control of the management interface while any legitimate administrator session is active.
- CVSS
- 9.2
- EPSS
- 0.47% 38.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.06.24