CVE-2019-8985: Buffer Overflow
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by userauth->userok in /bin/boa.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Netis WF2411 vulnerability?
The vulnerability ID for this Netis WF2411 vulnerability is CVE-2019-8985.
What is the severity of CVE-2019-8985?
The severity of CVE-2019-8985 is critical with a CVSS score of 9.8.
Which Netis WF2xxx devices are affected by CVE-2019-8985?
Netis WF2411 and possibly WF2411 through WF2880 devices are affected by CVE-2019-8985.
How can CVE-2019-8985 be exploited?
CVE-2019-8985 can be exploited through a stack-based buffer overflow that does not require authentication, leading to denial of service (device restart) or remote code execution.
What is the fix for CVE-2019-8985?
There is no official fix for CVE-2019-8985 at the moment, but it is recommended to update the firmware of the affected Netis devices to a patched version once it becomes available.