High severity8.8NVD Advisory· Published Feb 12, 2020· Updated Jun 17, 2026
CVE-2020-8946
CVE-2020-8946
Description
Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/sys_log_clean.cgi log_3g_type parameter.
Affected products
3- Netis/WF2471description
- cpe:2.3:o:netis-systems:wf2471_firmware:1.2.30142:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- sku11army.blogspot.com/2020/02/netis-authenticated-rce-on-wf2471.htmlnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.