CVE-2026-35018 Details
Description
NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands as root by injecting shell metacharacters into the username JSON parameter processed by the dalStorage_addUserAccount function. Attackers can exploit the unsafe concatenation of user-supplied input into a shell command string passed to rut_doSystemAction without sanitization to achieve full root-level command execution on the underlying operating system.
A remote code execution vulnerability has been identified in NetComm NF20MESH routers running firmware R6B031 and earlier. This vulnerability allows authenticated attackers to execute arbitrary commands as root. The issue arises from the dalStorage_addUserAccount function, where the username JSON parameter is improperly sanitized before being concatenated into a shell command. Exploitation of this vulnerability enables full root-level command execution on the device's operating system.
Users should update to NetComm's firmware version R6B032, which addresses this vulnerability. If immediate updating is not possible, it is recommended to change default passwords, avoid exposing the device to the public internet, and segment the device from sensitive internal assets.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 23, 2026CISA-ADP
Assessed Jun 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| NetComm NF20MESH | <= R6B031 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |
Volerion