CVE-2017-11646: Netcomm 4gt101w Bootloader

High severity, CVSS 8.8. EPSS: 0.4% chance of exploitation in the next 30 days.

NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to CSRF attacks, as demonstrated by using administration.html to disable the firewall. They does not contain any token that can mitigate CSRF vulnerabilities within the device.

Affected products

  • Netcomm 4gt101w Bootloader: version 1.1.3 only
  • Netcomm 4gt101w Software: version 1.1.8.8 only

Published 2017-07-28. Last modified 2026-06-17.