Security Advisory

CVE-2022-4874

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2023-01-11 20:39:25
Last updated 2025-11-04 19:14:31
Assigner certcc
CVSS score not scored
State PUBLISHED

Description

Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a "fake login" to give the request an active session to load the file and not redirect to the login page.