CVE-2025-67446
Received Received - Intake
Authentication Bypass in Neterbit NW-431F Router

Publication date: 2026-06-04

Last updated on: 2026-06-04

Assigner: MITRE

Description
Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting it to "admin"), an attacker can bypass the authentication schema and gain unauthorized access to admin functionalities.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-04
Last Modified
2026-06-04
Generated
2026-06-04
AI Q&A
2026-06-04
EPSS Evaluated
N/A
NVD
Affected Vendors & Products
Showing 7 associated CPEs
Vendor Product Version / Range
neterbit nw-431f_router nw-431f-20241014-ir03
neterbit nw-661d_ac1200_4g_td-lte_wireless_router *
neterbit nw-651d_4g_td-lte_router *
neterbit m920_v2_4g_lte_router *
neterbit nsl-224_modem *
neterbit nes-1005c *
neterbit ngs-1008a *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-384 Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2025-67446 is an improper authentication vulnerability affecting the Neterbit NW-431F Router and some related models. The router uses a weak and predictable cookie value for authentication. An attacker can exploit this by modifying the cookie value, for example setting it to "admin", to bypass the authentication mechanism.

By doing so, the attacker gains unauthorized access to administrative functionalities without needing valid credentials.


How can this vulnerability impact me? :

This vulnerability allows an attacker to bypass authentication and gain unauthorized administrative access to the affected router.

  • The attacker can control router settings, potentially disrupting network operations.
  • Sensitive network configurations and data could be exposed or altered.
  • The attacker could use the compromised router as a foothold to launch further attacks within the network.

Overall, this leads to a high risk of confidentiality, integrity, and availability impacts on the network.


How can this vulnerability be detected on my network or system? Can you suggest some commands?

This vulnerability can be detected by checking if the router's authentication mechanism uses a weak or predictable cookie value. Specifically, you can test if modifying the authentication cookie (for example, setting it to "admin") allows bypassing the login page and gaining administrative access.

A practical approach is to access the router's login page, then use a tool like curl or a browser developer console to modify the "username" cookie to "admin" and attempt to access the root or admin page. If access is granted without proper authentication, the vulnerability exists.

  • Example curl command to test authentication bypass by modifying the cookie:
  • curl -v --cookie "username=admin" http://<router-ip>/
  • Replace <router-ip> with the IP address of your Neterbit NW-431F router.

What immediate steps should I take to mitigate this vulnerability?

Since the vulnerability arises from a weak and predictable authentication cookie and no fixed software version is currently available, immediate mitigation steps include:

  • Restrict access to the router's administrative interface by limiting it to trusted IP addresses or internal networks only.
  • Disable remote management features if enabled to prevent external attackers from exploiting the vulnerability.
  • Monitor network traffic for suspicious requests that attempt to modify authentication cookies.
  • Change default passwords and ensure strong credentials are used, although this does not fully mitigate the cookie weakness.
  • Contact Neterbit support or monitor their official channels for updates or patches addressing this vulnerability.

How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:

The vulnerability allows an attacker to bypass authentication and gain unauthorized administrative access to the affected Neterbit routers. This unauthorized access can lead to exposure or manipulation of sensitive data, which may result in non-compliance with data protection regulations such as GDPR and HIPAA that require strict access controls and protection of personal and health information.

Because the vulnerability compromises the integrity and confidentiality of the device's administrative functions, organizations using these routers could face increased risk of data breaches or unauthorized data processing, potentially violating regulatory requirements.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart