CVE-2022-4873: Netcommwireless NF20 Firmware
Critical severity, CVSS 9.8. EPSS: 7.2% chance of exploitation in the next 30 days.
On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a known location.
Affected products
- Netcommwireless NF20 Firmware: before r6b025 (fixed in r6b025)
- Netcommwireless NF20MESH Firmware: before r6b025 (fixed in r6b025)
- Netcommwireless NL1902 Firmware: before r6b025 (fixed in r6b025)
Published 2023-01-11. Last modified 2026-06-17.