彙總 netcommwireless 相關全部產品的 CVE 與安全漏洞情報,包括 CVSS、EPSS、公開時間與漏洞情報資料。
常見弱點模式包括 跨站腳本、路徑處理缺陷、CSRF與記憶體損壞,在 軟體部署與生產負載 使用場景中可能帶來 檔案覆寫、工作階段劫持與記憶體損壞 等風險。
相關漏洞資料主要來源於公開漏洞披露與安全公告,可用於評估歷史漏洞暴露面與修補優先順序。
| CVE | 摘要 | 來源 | 最高 CVSS | EPSS % | 公開時間 | 更新時間 |
|---|---|---|---|---|---|---|
| CVE-2022-4874 | Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a "fake login" to give the request an active session to load the file and not redirect to the login page. | [email protected] | 7.5 | 11.01% | 2023-01-11 | 2026-06-17 |
| CVE-2022-4873 | On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a known location. | [email protected] | 9.8 | 7.17% | 2023-01-11 | 2026-06-17 |
| CVE-2018-14785 | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the device is listed openly without authentication. | [email protected] | 7.5 | 2.21% | 2018-08-10 | 2026-06-16 |
| CVE-2018-14784 | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable to several cross-site scripting attacks, allowing a remote attacker to run arbitrary code on the device. | [email protected] | 6.1 | 0.98% | 2018-08-10 | 2026-06-16 |
| CVE-2018-14783 | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forgery condition can occur, allowing an attacker to change passwords of the device remotely. | [email protected] | 8.8 | 0.67% | 2018-08-10 | 2026-06-16 |
| CVE-2018-14782 | NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and profiles without authenticating the user. | [email protected] | 7.5 | 1.62% | 2018-08-10 | 2026-06-16 |
| CVE-2015-6024 | ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the DIA_IPADDRESS parameter. | [email protected] | 9.8 | 26.10% | 2017-02-09 | 2026-06-16 |
| CVE-2015-6023 | ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intended access restrictions via a direct request. NOTE: this issue can be combined with CVE-2015-6024 to execute arbitrary commands. | [email protected] | 7.3 | 10.98% | 2017-02-09 | 2026-06-16 |
| CVE-2014-4871 | Cross-site scripting (XSS) vulnerability in wlsecurity.html on NetCommWireless NB604N routers with firmware before GAN5.CZ56T-B-NC.AU-R4B030.EN allows remote attackers to inject arbitrary web script or HTML via the wlWpaPsk parameter. | [email protected] | 4.3 | 1.11% | 2014-10-07 | 2026-06-16 |