CVE-2019-19356: Netis WF2419 Devices Remote Code Execution Vulnerability
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.
Other sources
Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netis WF2419to a version that resolves this vulnerability.Fixed in V1.2.31805 - Upgrade
Upgrade
Netis WF2419to a version that resolves this vulnerability.Fixed in V2.2.36123 - Compensating control
Restrict access to the Netis WF2419 web management page so only trusted users/IPs can authenticate and use the tracert diagnostic tool (to reduce exposure to the authenticated RCE as root).
Event History
Frequently Asked Questions
What is CVE-2019-19356?
CVE-2019-19356 is a vulnerability that allows authenticated remote code execution as root through the router Web management page on Netis WF2419 Devices.
What is the severity of CVE-2019-19356?
CVE-2019-19356 has a severity rating of 7.5 (high).
Which software versions are affected by CVE-2019-19356?
CVE-2019-19356 affects firmware version V1.2.31805 and V2.2.36123 of the Netis WF2419 Devices.
How can I exploit CVE-2019-19356?
To exploit CVE-2019-19356, you need to establish an authenticated connection to the router Web management page.
Is there a fix for CVE-2019-19356?
To fix CVE-2019-19356, it is recommended to update the firmware of the Netis WF2419 Devices to a secure version.