9.8
CVSSv3

CVE-2021-39290

Published: 23/08/2021 Updated: 02/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware prior to 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netmodule netmodule router software

Exploits

NetModule Router Software versions prior to 430113, 440111, and 450105 suffer from insecure password handling and session fixation vulnerabilities ...

Mailing Lists

SEC Consult Vulnerability Lab Security Advisory < 20210820-0 > ======================================================================= title: Multiple Vulnerabilities in NetModule Router Software product: NetModule Router Software (NRSW) vulnerable version: Before 430113, 440111, 450105 fixed version: ...