Show plain JSON{"configurations": [{"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:o:netcommwireless:nf20_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "447DAC30-D02D-43A7-9C11-9B29D3AE6292", "versionEndExcluding": "r6b025", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:h:netcommwireless:nf20:-:*:*:*:*:*:*:*", "matchCriteriaId": "C9BF282B-6B02-492D-A248-80D6C5DD0B50", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:o:netcommwireless:nf20mesh_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "492B3CE0-A18A-4D6E-A20F-5CD00D8FC234", "versionEndExcluding": "r6b025", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:h:netcommwireless:nf20mesh:-:*:*:*:*:*:*:*", "matchCriteriaId": "79CF62CC-4353-4090-8D85-5F8126A029EB", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}, {"nodes": [{"cpeMatch": [{"criteria": "cpe:2.3:o:netcommwireless:nl1902_firmware:*:*:*:*:*:*:*:*", "matchCriteriaId": "131C4DCD-D115-40AE-A53D-2C3B4799CBD5", "versionEndExcluding": "r6b025", "vulnerable": true}], "negate": false, "operator": "OR"}, {"cpeMatch": [{"criteria": "cpe:2.3:h:netcommwireless:nl1902:-:*:*:*:*:*:*:*", "matchCriteriaId": "B02578F1-96D9-4A0C-A27E-F08518A7CA55", "vulnerable": false}], "negate": false, "operator": "OR"}], "operator": "AND"}], "descriptions": [{"lang": "en", "value": "Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application performs a check for the existence of specific characters in the URL (.css, .png etc). If it exists, it performs a \"fake login\" to give the request an active session to load the file and not redirect to the login page."}, {"lang": "es", "value": "La omisi\u00f3n de autenticaci\u00f3n en los modelos de router Netcomm NF20MESH, NF20 y NL1902 permite que un usuario no autenticado acceda al contenido. Para ofrecer contenido est\u00e1tico, la aplicaci\u00f3n verifica la existencia de caracteres espec\u00edficos en la URL (.css, .png, etc.). Si existe, realiza un \"inicio de sesi\u00f3n falso\" para darle a la solicitud una sesi\u00f3n activa para cargar el archivo y no redirigir a la p\u00e1gina de inicio de sesi\u00f3n."}], "id": "CVE-2022-4874", "lastModified": "2024-11-21T07:36:06.980", "metrics": {"cvssMetricV31": [{"cvssData": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 7.5, "baseSeverity": "HIGH", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1"}, "exploitabilityScore": 3.9, "impactScore": 3.6, "source": "nvd@nist.gov", "type": "Primary"}]}, "published": "2023-01-11T21:15:10.373", "references": [{"source": "cret@cert.org", "tags": ["Exploit", "Third Party Advisory"], "url": "https://github.com/scarvell/advisories/blob/main/2022_netcomm_nf20mesh_unauth_rce.md"}, {"source": "af854a3a-2127-422b-91ae-364da2661108", "tags": ["Exploit", "Third Party Advisory"], "url": "https://github.com/scarvell/advisories/blob/main/2022_netcomm_nf20mesh_unauth_rce.md"}], "sourceIdentifier": "cret@cert.org", "vulnStatus": "Modified", "weaknesses": [{"description": [{"lang": "en", "value": "CWE-287"}], "source": "nvd@nist.gov", "type": "Primary"}]}