Vendor CVEs
Netis
All CVEs
67 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-20071 | Med | 0.42 | 6.5 | 0.01 | Dec 30, 2019 | On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs. | ||
| CVE-2019-20076 | Med | 0.40 | 6.1 | 0.02 | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configuration). | ||
| CVE-2019-20075 | Med | 0.40 | 6.1 | 0.02 | Dec 30, 2019 | On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic). | ||
| CVE-2019-20073 | Med | 0.40 | 6.1 | 0.02 | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration). | ||
| CVE-2019-20072 | Med | 0.40 | 6.1 | 0.02 | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration). | ||
| CVE-2019-20070 | Med | 0.40 | 6.1 | 0.01 | Dec 30, 2019 | On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking Configuration). | ||
| CVE-2018-6190 | Med | 0.38 | 5.4 | 0.02 | Jan 24, 2018 | Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page. | ||
| CVE-2023-0113 | Med | 0.35 | 5.3 | 0.01 | Jan 7, 2023 | A vulnerability was found in Netis Netcore Router up to 2.2.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to information disclosure. The attack… | ||
| CVE-2018-5967 | Med | 0.35 | 5.4 | 0.01 | Jan 25, 2018 | Netis WF2419 V2.2.36123 devices allow XSS via the Description parameter on the Bandwidth Control Rule Settings page. | ||
| CVE-2024-33793 | Med | 0.34 | 5.3 | 0.00 | May 3, 2024 | netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test page. | ||
| CVE-2024-33791 | Med | 0.30 | 4.6 | 0.00 | May 3, 2024 | A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function. | ||
| CVE-2024-48455 | Low | 0.21 | 2.7 | 0.06 | Jan 6, 2025 | An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and… | ||
| CVE-2023-0114 | Low | 0.21 | 3.3 | 0.00 | Jan 7, 2023 | A vulnerability was found in Netis Netcore Router. It has been rated as problematic. Affected by this issue is some unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to cleartext storage in a file or on disk. Local access is… | ||
| CVE-2025-9119 | Low | 0.16 | 2.4 | 0.00 | Aug 18, 2025 | A vulnerability was determined in Netis WF2419 1.2.29433. This vulnerability affects unknown code of the file /index.htm of the component Wireless Settings Page. This manipulation of the argument SSID with the input <img/src/onerror=prompt(8)> causes cross site scripting. Remote… | ||
| CVE-2025-1617 | Low | 0.16 | 2.4 | 0.00 | Feb 24, 2025 | A vulnerability, which was classified as problematic, was found in Netis WF2780 2.1.41925. This affects an unknown part of the component Wireless 2.4G Menu. The manipulation of the argument SSID leads to cross site scripting. It is possible to initiate the attack remotely. The… | ||
| CVE-2025-2922 | Low | 0.13 | 2.0 | 0.00 | Mar 28, 2025 | A vulnerability classified as problematic was found in Netis WF-2404 1.1.124EN. Affected by this vulnerability is an unknown functionality of the component BusyBox Shell. The manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack on… | ||
| CVE-2025-2920 | Low | 0.13 | 2.0 | 0.00 | Mar 28, 2025 | A vulnerability was found in Netis WF-2404 1.1.124EN. It has been rated as problematic. This issue affects some unknown processing of the file /еtc/passwd. The manipulation leads to use of weak hash. It is possible to launch the attack on the physical device. The complexity of… |
- risk 0.42cvss 6.5epss 0.01
On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.
- risk 0.40cvss 6.1epss 0.02
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configuration).
- risk 0.40cvss 6.1epss 0.02
On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic).
- risk 0.40cvss 6.1epss 0.02
On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration).
- risk 0.40cvss 6.1epss 0.02
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration).
- risk 0.40cvss 6.1epss 0.01
On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking Configuration).
- risk 0.38cvss 5.4epss 0.02
Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.
- risk 0.35cvss 5.3epss 0.01
A vulnerability was found in Netis Netcore Router up to 2.2.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to information disclosure. The attack…
- risk 0.35cvss 5.4epss 0.01
Netis WF2419 V2.2.36123 devices allow XSS via the Description parameter on the Bandwidth Control Rule Settings page.
- risk 0.34cvss 5.3epss 0.00
netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary OS commands via a crafted payload to the ping test page.
- risk 0.30cvss 4.6epss 0.00
A cross-site scripting (XSS) vulnerability in netis-systems MEX605 v2.00.06 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the getTimeZone function.
- risk 0.21cvss 2.7epss 0.06
An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and…
- risk 0.21cvss 3.3epss 0.00
A vulnerability was found in Netis Netcore Router. It has been rated as problematic. Affected by this issue is some unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to cleartext storage in a file or on disk. Local access is…
- risk 0.16cvss 2.4epss 0.00
A vulnerability was determined in Netis WF2419 1.2.29433. This vulnerability affects unknown code of the file /index.htm of the component Wireless Settings Page. This manipulation of the argument SSID with the input <img/src/onerror=prompt(8)> causes cross site scripting. Remote…
- risk 0.16cvss 2.4epss 0.00
A vulnerability, which was classified as problematic, was found in Netis WF2780 2.1.41925. This affects an unknown part of the component Wireless 2.4G Menu. The manipulation of the argument SSID leads to cross site scripting. It is possible to initiate the attack remotely. The…
- risk 0.13cvss 2.0epss 0.00
A vulnerability classified as problematic was found in Netis WF-2404 1.1.124EN. Affected by this vulnerability is an unknown functionality of the component BusyBox Shell. The manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack on…
- risk 0.13cvss 2.0epss 0.00
A vulnerability was found in Netis WF-2404 1.1.124EN. It has been rated as problematic. This issue affects some unknown processing of the file /еtc/passwd. The manipulation leads to use of weak hash. It is possible to launch the attack on the physical device. The complexity of…
Page 2 of 2