See how netis-systems compares to other vendors in security performance
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wpsapssid5g parameter
netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the tracert page.
An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component.
There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeupmac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerability is exploited via a crafted payload.
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pinhost parameter in the WPS Settings.
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings.
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings.
A vulnerability classified as critical has been found in Netis Netcore Router. This affects an unknown part. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The identifier VDB-217593 was assigned to this vulnerability.
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by userauth->userok in /bin/boa.
An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnostic tools component in the admin management interface.
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via a crafted HTTP request.
On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.
Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/syslogclean.cgi log3gtype parameter.
A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete Address Reservation List settings.
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the configsequence parameter in otherpara of cgitest.cgi.
A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN004904c8 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the environment variable value CONTENTLENGTH, causing the program to crash and potentially leading to a denial-of-service (DoS) attack.
A null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN0048a728 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the CONTENTLENGTH variable, causing the program to crash and potentially leading to a denial-of-service (DoS) attack.
A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN00471994 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wlbaseset in the payload, which can cause the program to crash and potentially lead to a Denial of Service (DoS) attack.
A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the Function00465620 of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of specifyparame in the payload, which can cause the program to crash and potentially lead to a Denial of Service (DoS) attack.
A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN00476598 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wlbaseset5g in the payload, which can cause the program to crash and potentially lead to a Denial of Service (DoS) attack.
A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN00473154 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wlsecset5g and wlsecrpset5g in the payload, which can cause the program to crash and potentially lead to a Denial of Service (DoS) attack.
A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN00475e1c function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wdskeywep in the payload, which can cause the program to crash and potentially lead to a Denial of Service (DoS) attack.
A buffer overflow vulnerability has been discovered in the Netis WF2880 v2.1.40207 in the FUN004743f8 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wlsecset in the payload, which may cause the program to crash and potentially lead to a Denial of Service (DoS) attack.
A buffer overflow vulnerability has been discovered in the Netis WF2880 v2.1.40207 in the FUN0047151c function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wdsset in the payload, which can cause the program to crash and potentially lead to a Denial of Service (DoS) attack.
A buffer overflow vulnerability has been discovered in Netis WF2880 v2.1.40207 in the FUN0046f984 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the value of wladvancedset in the payload, which can cause the program to crash and lead to a Denial of Service (DoS) attack.