Netmodule develops a focused line of industrial networking and remote-access appliances, primarily routers and cellular gateways designed for mission-critical field deployments, with its disclosed vulnerabilities concentrating in products such as the NB1601, NB1800, and NB2800 series. The exposure recurs through command-injection variants, path-traversal flaws, and credential-handling weaknesses—attack surface typical of embedded devices that blend web administration interfaces, command-line access, and file-system operations—and skews toward serious severity outcomes. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netmodule over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-0861HIGH NetModule NSRW web administration interface executes an OS command constructed with unsanitized user input. A successful exploit could allow an authenticated user to execute arbitr | Feb 16, 2023 | 8.8 | 35 | NO | NO |
CVE-2021-39290CRITICAL Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, N | Aug 23, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-39291HIGH Certain NetModule devices allow credentials via GET parameters to CLI-PHP. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601 | Aug 23, 2021 | 8.8 | 26 | NO | NO |
CVE-2023-0862HIGH The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file uploads and deletion. By uploading malicious files to the web r | Feb 16, 2023 | 8.8 | 25 | NO | NO |
CVE-2021-39289HIGH Certain NetModule devices have Insecure Password Handling (cleartext or reversible encryption), These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: | Aug 23, 2021 | 7.5 | 23 | NO | NO |
CVE-2023-46306MEDIUM The web administration interface in NetModule Router Software (NRSW) 4.6 before 4.6.0.106 and 4.8 before 4.8.0.101 executes an OS command constructed with unsanitized user input: s | Oct 22, 2023 | 6.6 | 22 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netmodule.
Media articles that mention a CVE ID that affects a product developed by Netmodule — matched by CVE ID, not by vendor name.