Changeflow GovPing Data Privacy & Cybersecurity Belden NetModule Router Software Vulnerabilitie...
Priority review Notice Added Final

Belden NetModule Router Software Vulnerabilities Allow Remote Code Execution

Favicon for www.cert.ssi.gouv.fr CERT-FR Security Advisories
Published
Detected
Email

Summary

CERT-FR issued advisory CERTFR-2026-AVI-0390 notifying of multiple critical vulnerabilities (CVE-2025-15467, CVE-2025-69419) in Belden NetModule Router Software versions prior to 5.0.0.102. The vulnerabilities allow remote attackers to execute arbitrary code and cause denial of service. Organizations using affected NetModule routers should refer to vendor's PSIRT-5_OpenSSL_Vulnerabilities_NRSW bulletin for patch information.

What changed

CERT-FR identified multiple critical vulnerabilities in Belden NetModule Router Software (NRSW) stemming from OpenSSL issues, documented as CVE-2025-15467 and CVE-2025-69419. The vulnerabilities affect all versions prior to 5.0.0.102 and enable remote code execution and remote denial of service attacks. Belden PSIRT has published corresponding patch bulletin PSIRT-5OpenSSLVulnerabilities_NRSW.

Organizations using NetModule Router Software should immediately identify affected deployments and apply vendor-provided patches (version 5.0.0.102 or later). Given the remote code execution risk, affected entities should treat this as high priority and verify patch status across all deployed units. No specific compliance deadline is mandated by CERT-FR; remediation timeline should follow vendor guidance and internal risk assessment.

What to do next

  1. Identify all NetModule Router Software installations and verify current version
  2. Update affected devices to version 5.0.0.102 or later using Belden's official patch
  3. Monitor for indicators of compromise given remote code execution risk

Archived snapshot

Apr 2, 2026

GovPing captured this document from the original source. If the source has since changed or been removed, this is the text as it existed at that time.

Premier Ministre S.G.D.S.N

Agence nationale
de la sécurité des
systèmes d'information

Paris, le 02 avril 2026 N° CERTFR-2026-AVI-0390 Affaire suivie par: CERT-FR

Avis du CERT-FR

Objet: Multiples vulnérabilités dans Belden NetModule Router Software

Gestion du document

| Référence | CERTFR-2026-AVI-0390 |
| Titre | Multiples vulnérabilités dans Belden NetModule Router Software |
| Date de la première version | 02 avril 2026 |
| Date de la dernière version | 02 avril 2026 |
| Source(s) | Bulletin de sécurité Belden PSIRT-5OpenSSLVulnerabilities_NRSW du 02 avril 2026 |
Une gestion de version détaillée se trouve à la fin de ce document.


Risques

  • Déni de service à distance
  • Exécution de code arbitraire à distance

Systèmes affectés

  • NetModule Router Software (NRSW) versions antérieures à 5.0.0.102

Résumé

De multiples vulnérabilités ont été découvertes dans Belden NetModule Router Software. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un déni de service à distance.

Solutions

Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

Documentation


Gestion détaillée du document

  1. le 02 avril 2026 Version initiale

Get daily alerts for CERT-FR Security Advisories

Daily digest delivered to your inbox.

Free. Unsubscribe anytime.

About this page

What is GovPing?

Every important government, regulator, and court update from around the world. One place. Real-time. Free. Our mission

What's from the agency?

Source document text, dates, docket IDs, and authority are extracted directly from CERT-FR.

What's AI-generated?

The summary, classification, recommended actions, deadlines, and penalty information are AI-generated from the original text and may contain errors. Always verify against the source document.

Last updated

Classification

Agency
CERT-FR
Published
April 2nd, 2026
Instrument
Notice
Legal weight
Non-binding
Stage
Final
Change scope
Minor
Document ID
CERTFR-2026-AVI-0390

Who this affects

Applies to
Technology companies Telecommunications firms Government agencies
Industry sector
3341 Computer & Electronics Manufacturing 5170 Telecommunications 9211 Government & Public Administration
Activity scope
Vulnerability Disclosure Network Infrastructure Security
Threshold
NetModule Router Software (NRSW) versions prior to 5.0.0.102
Geographic scope
France FR

Taxonomy

Primary area
Cybersecurity
Operational domain
IT Security
Compliance frameworks
NIST CSF
Topics
Defense & National Security Data Privacy

Get alerts for this source

We'll email you when CERT-FR Security Advisories publishes new changes.

Free. Unsubscribe anytime.

You're subscribed!