CVE-2019-19356: Netis WF2419 Devices Remote Code Execution Vulnerability

Published Feb 7, 2020
·
Updated

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

Other sources

Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.

CISA

Affected Software

7 affected components
Netis WF2419 Devices
netis-systems Wf2419 Firmware=1.2.31805
netis-systems Wf2419 Firmware=2.2.36123
netis-systems Wf2419
All of the following
Any of the following
netis-systems Wf2419 Firmware=1.2.31805
netis-systems Wf2419 Firmware=2.2.36123
netis-systems Wf2419

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Netis WF2419 to a version that resolves this vulnerability.

    Fixed in V1.2.31805
  2. Upgrade

    Upgrade Netis WF2419 to a version that resolves this vulnerability.

    Fixed in V2.2.36123
  3. Compensating control

    Restrict access to the Netis WF2419 web management page so only trusted users/IPs can authenticate and use the tracert diagnostic tool (to reduce exposure to the authenticated RCE as root).

Event History

Feb 7, 2020
CVE Published
via MITRE·10:49 PM
Data Sourced
via MITRE·10:49 PM
Description
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 3, 2021
Known Exploited
via CISA·12:00 AM
Mar 17, 58454
Event
04:56 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2019-19356?

CVE-2019-19356 is a vulnerability that allows authenticated remote code execution as root through the router Web management page on Netis WF2419 Devices.

2

What is the severity of CVE-2019-19356?

CVE-2019-19356 has a severity rating of 7.5 (high).

3

Which software versions are affected by CVE-2019-19356?

CVE-2019-19356 affects firmware version V1.2.31805 and V2.2.36123 of the Netis WF2419 Devices.

4

How can I exploit CVE-2019-19356?

To exploit CVE-2019-19356, you need to establish an authenticated connection to the router Web management page.

5

Is there a fix for CVE-2019-19356?

To fix CVE-2019-19356, it is recommended to update the firmware of the Netis WF2419 Devices to a secure version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203