CRITICAL · 9.8

CVE-2021-39290

Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB270...

Vulnerability Description

Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
NetmoduleNetmodule Router Software< 4.3.0.113
NetmoduleNb1600-
NetmoduleNb1601-
NetmoduleNb1800-
NetmoduleNb1810-
NetmoduleNb2700-
NetmoduleNb2710-
NetmoduleNb2800-
NetmoduleNb2810-
NetmoduleNb3700-
NetmoduleNb3701-
NetmoduleNb3710-
NetmoduleNb3711-
NetmoduleNb3720-
NetmoduleNb3800-
NetmoduleNb800-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-39290?

CVE-2021-39290 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB270...

How severe is CVE-2021-39290?

CVE-2021-39290 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-39290?

Check the references section above for vendor advisories and patch information. Affected products include: Netmodule Netmodule Router Software, Netmodule Nb1600, Netmodule Nb1601, Netmodule Nb1800, Netmodule Nb1810.