VYPR

NW-431F Router

by Neterbit

CVEs (4)

  • CVE-2025-67447CriJun 4, 2026
    risk 0.64cvss 9.8epss

    The network diagnosis (ping) module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to OS command injection. The application does not properly sanitize user input in the IP address field before passing it to the system's ping command. An attacker can inject…

  • CVE-2025-67446CriJun 4, 2026
    risk 0.64cvss 9.8epss

    Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie value (e.g., setting it to "admin"), an attacker can bypass the authentication…

  • CVE-2025-69755HigJun 4, 2026
    risk 0.53cvss 8.2epss

    An issue in Neterbit NW-431F Router vNW-431F-20241014-IR03 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted command to the at_command.asp interface

  • CVE-2025-67448HigJun 4, 2026
    risk 0.46cvss 7.1epss

    The SMS module in Neterbit NW-431F Router 20241014-IR03 and before is vulnerable to stored XSS. The application does not properly sanitize user input in SMS messages before storing and displaying them. An attacker can send an SMS containing a malicious XSS payload, which will be…