Back to overview

CVE-2025-67446

CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting it to "admin"), an attacker can bypass the authentication schema and gain unauthorized access to admin functionalities.

Metadata

CVE ID
CVE-2025-67446
State
PUBLISHED
Assigner
mitre
Reserved
2025-12-08 00:00 UTC
Published
2026-06-04 00:00 UTC
Last updated
2026-06-04 17:07 UTC
Primary CWE
CWE-384
CWE-384 Session Fixation
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-384 adp CWE-384 Session Fixation
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:U/UI:N
Back to overview