VYPR

Wf2780 Firmware

by Netis

CVEs (4)

  • CVE-2021-26747CriFeb 18, 2021
    risk 0.68cvss 9.8epss 0.54

    Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.

  • CVE-2024-25850CriFeb 22, 2024
    risk 0.65cvss 9.8epss 0.19

    Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter

  • CVE-2024-25851HigFeb 22, 2024
    risk 0.52cvss 8.0epss 0.02

    Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgitest.cgi.

  • CVE-2025-50635HigAug 13, 2025
    risk 0.49cvss 7.5epss 0.00

    A null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_0048a728 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the CONTENT_LENGTH variable, causing the program to crash…