Certain NetModule devices allow Limited Session Fixation via PHPSESSID. These models with firmware before 4.3.0.113, 4.4.0.111, and 4.5.0.105 are affected: NB800, NB1600, NB1601, NB1800, NB1810, NB2700, NB2710, NB2800, NB2810, NB3700, NB3701, NB3710, NB3711, NB3720, and NB3800.
References
Link | Resource |
---|---|
https://seclists.org/fulldisclosure/2021/Aug/22 | Exploit Mailing List Third Party Advisory |
https://www.netmodule.com | Vendor Advisory |
https://seclists.org/fulldisclosure/2021/Aug/22 | Exploit Mailing List Third Party Advisory |
https://www.netmodule.com | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 06:19
Type | Values Removed | Values Added |
---|---|---|
References | () https://seclists.org/fulldisclosure/2021/Aug/22 - Exploit, Mailing List, Third Party Advisory | |
References | () https://www.netmodule.com - Vendor Advisory |
02 Nov 2023, 15:48
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:o:netmodule:nb1601_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb3701_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb800_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb3700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb3720_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb1800_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb3710_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb2800_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb2810_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb3711_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb2700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb1810_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb1600_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netmodule:nb3800_firmware:*:*:*:*:*:*:*:* |
cpe:2.3:a:netmodule:netmodule_router_software:*:*:*:*:*:*:*:* |
First Time |
Netmodule netmodule Router Software
|
Information
Published : 2021-08-23 05:15
Updated : 2024-11-21 06:19
NVD link : CVE-2021-39290
Mitre link : CVE-2021-39290
CVE.ORG link : CVE-2021-39290
JSON object : View
Products Affected
netmodule
- nb2700
- nb1800
- nb1810
- nb2800
- nb3700
- nb3711
- nb2710
- nb1600
- nb3710
- netmodule_router_software
- nb3720
- nb3800
- nb800
- nb2810
- nb1601
- nb3701
CWE
CWE-384
Session Fixation