CVE-2021-26914 is a critical Java deserialization vulnerability affecting NetMotion Mobility versions before 11.73 and 12.x before 12.02. This flaw allows unauthenticated remote attackers to execute arbitrary code as SYSTEM, posing a severe risk to affected systems. With a CVSS score of 8.1 (HIGH), it has a low attack complexity and no user interaction required, enabling full compromise of confidentiality, integrity, and availability. Exploit intelligence indicates a Metasploit module is available, and community discussions suggest active exploitation, despite no official KEV listing or widespread media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.73CPE matchmatch criteria | cpe:2.3:a:netmotionsoftware:netmotion_mobility:*:*:*:*:*:*:*:* | ||
>= 12.0, < 12.02CPE matchmatch criteria | cpe:2.3:a:netmotionsoftware:netmotion_mobility:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.