Vulnerability record · CVE-2021-26914 · published 8 February 2021
CVE-2021-26914: NetMotion Mobility Java deserialization allows unauthenticated RCE as SYSTEM
NNetmotionsoftware · Netmotion Mobility
NetMotion Mobility before 11.73 and 12.x before 12.02 deserializes untrusted data in MvcUtil valueStringToObject, letting an unauthenticated remote attacker execute arbitrary code. Because the code runs as SYSTEM, a successful hit gives full control of the Mobility server.
Description
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityUnauthenticated network-reachable RCE as SYSTEM with public exploit references and very high EPSS, though not yet in KEV.
What it is
NetMotion Mobility before 11.73 and 12.x before 12.02 deserializes untrusted data in MvcUtil valueStringToObject, letting an unauthenticated remote attacker execute arbitrary code. Because the code runs as SYSTEM, a successful hit gives full control of the Mobility server.
Impact
An attacker gains remote code execution with SYSTEM privileges on the NetMotion Mobility server, enabling full compromise of the host and any data or credentials it handles.
Attack surface
Reached over the network via the Mobility web server; the CVSS vector shows no privileges and no user interaction required, so the flaw is exploitable pre-authentication.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.777, 99.5th percentile) and multiple references are tagged Exploit, indicating public exploit code exists.
What to do
- Upgrade NetMotion Mobility to 11.73 or 12.02 (or later) as directed by the vendor advisory.
- If immediate patching is not possible, restrict network access to the Mobility web server to trusted management networks only.
- Monitor and block deserialization attack patterns at the web tier (WAF or reverse proxy) as a temporary control.
- Confirm the Mobility web server is not exposed to the internet and review firewall rules for unnecessary exposure.
Detection
- Review Mobility web server logs for anomalous requests to MvcUtil or deserialization-related endpoints.
- Alert on unexpected child processes spawned by the Mobility/Java service, especially those running as SYSTEM.
- Monitor for outbound connections from the Mobility server to unknown hosts that could indicate post-exploitation activity.
- Hunt for known Java deserialization gadget payloads in HTTP request bodies reaching the Mobility web server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/162617/NetMotion-Mobility-Server-MvcUtil-Java-Deserialization.html | ExploitThird Party AdvisoryVDB Entry |
| https://ssd-disclosure.com/?p=4676 | ExploitThird Party Advisory |
| https://ssd-disclosure.com/ssd-advisory-netmotion-mobility-server-multiple-deserialization-of-untrusted-data-lead-to-rce | ExploitThird Party Advisory |
| https://www.netmotionsoftware.com/security-advisories/security-vulnerability-in-mobility-web-server-november-19-2020 | Vendor Advisory |
| http://packetstormsecurity.com/files/162617/NetMotion-Mobility-Server-MvcUtil-Java-Deserialization.html | ExploitThird Party AdvisoryVDB Entry |
| https://ssd-disclosure.com/?p=4676 | ExploitThird Party Advisory |
| https://ssd-disclosure.com/ssd-advisory-netmotion-mobility-server-multiple-deserialization-of-untrusted-data-lead-to-rce | ExploitThird Party Advisory |
| https://www.netmotionsoftware.com/security-advisories/security-vulnerability-in-mobility-web-server-november-19-2020 | Vendor Advisory |
Track CVE-2021-26914 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-26914), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.