Netcommwireless produces a focused line of wireless networking and mobile broadband devices, including the NWL-25 series and HSPA 3G10WVE, that operate at the edge of enterprise and consumer networks. Vulnerabilities affecting the vendor skew toward critical-severity outcomes and frequently acquire public exploit tooling, clustered around information-disclosure flaws, authentication weaknesses, web-application input handling (cross-site scripting and request forgery), and directory-enumeration exposures that are characteristic of embedded web interfaces. Defenders should prioritize inventory and access restriction for these devices, particularly older models; current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netcommwireless over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-6024CRITICAL ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shel | Feb 9, 2017 | 9.8 | 48 | NO | YES |
CVE-2022-4873CRITICAL On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer | Jan 11, 2023 | 9.8 | 34 | NO | NO |
CVE-2015-6023HIGH ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intended access restrictions via a dir | Feb 9, 2017 | 7.3 | 32 | NO | YES |
CVE-2018-14783HIGH NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forgery condition can occur, allowing an attacker to change pass | Aug 10, 2018 | 8.8 | 27 | NO | NO |
CVE-2018-14785HIGH NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the device is listed openly without authentication. | Aug 10, 2018 | 7.5 | 25 | NO | NO |
CVE-2018-14782HIGH NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and profiles without authenticating t | Aug 10, 2018 | 7.5 | 25 | NO | NO |
CVE-2022-4874HIGH Authentication bypass in Netcomm router models NF20MESH, NF20, and NL1902 allows an unauthenticated user to access content. In order to serve static content, the application perfor | Jan 11, 2023 | 7.5 | 23 | NO | NO |
CVE-2018-14784MEDIUM NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable to several cross-site scripting attacks, allowing a remote a | Aug 10, 2018 | 6.1 | 22 | NO | NO |
CVE-2014-4871MEDIUM Cross-site scripting (XSS) vulnerability in wlsecurity.html on NetCommWireless NB604N routers with firmware before GAN5.CZ56T-B-NC.AU-R4B030.EN allows remote attackers to inject ar | Oct 7, 2014 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netcommwireless.
Media articles that mention a CVE ID that affects a product developed by Netcommwireless — matched by CVE ID, not by vendor name.