CVE-2018-25134: Synaccess Networks Inc Netbooter Np-02x/np-08x

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Synaccess netBooter NP-02x/NP-08x 6.8 contains an authentication bypass vulnerability in the webNewAcct.cgi script that allows unauthenticated attackers to create admin user accounts. Attackers can exploit the missing control check by sending crafted POST requests to create administrative accounts and gain unauthorized control over power supply management.

Affected products

  • Synaccess Networks Inc Netbooter Np-02x/np-08x: version 6.8C only; version 6.5C only; version 6.4BC only; version 6.4A only; version 6.10 only; version 5.53BC only

Published 2025-12-24. Last modified 2026-06-17.