CVE-2025-67446

Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting it to "admin"), an attacker can bypass the authentication schema and gain unauthorized access to admin functionalities.
Configurations

No configuration.

History

22 Jul 2026, 20:10

Type Values Removed Values Added
Summary
  • (es) Autenticación Inadecuada (Omisión de autenticación) existe en el Router Neterbit NW-431F 20241014-IR03 y anteriores. El router utiliza un valor de cookie débil/predecible para la autenticación. Al modificar el valor de la cookie (p. ej., estableciéndolo en 'admin'), un atacante puede omitir el esquema de autenticación y obtener acceso no autorizado a las funcionalidades de administrador.

04 Jun 2026, 18:16

Type Values Removed Values Added
CWE CWE-384
References () https://github.com/fun-beep/CVEs/tree/main/CVE-2025-67446 - () https://github.com/fun-beep/CVEs/tree/main/CVE-2025-67446 -

04 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-04 17:16

Updated : 2026-07-22 20:10


NVD link : CVE-2025-67446

Mitre link : CVE-2025-67446

CVE.ORG link : CVE-2025-67446


JSON object : View

Products Affected

No product.

CWE
CWE-384

Session Fixation