ZeroHour

CVE-2019-19356

KEV PoC ×3mass

Command Injection RCE as Root in Netis WF2419 Routers

CISA: Netis WF2419 Devices Remote Code Execution Vulnerability

CVSS 3.1
7.5 high
EPSS
28%p98
Published
()
KEV added
AI analysis

Netis WF2419 routers contain an operating-system command injection flaw (CWE-78) in the router's web management page that allows an attacker to execute arbitrary commands with root privileges. The flaw is triggered through the web management interface, where crafted input is passed to a system command without adequate sanitization, enabling unauthenticated or low-privilege access to escalate to full command execution as root. An attacker who exploits it gains complete control of the router — root-level code execution — which can be used to intercept or manipulate traffic, pivot into the local network, or enlist the device in a botnet. Any user or organization running a Netis WF2419 router is affected, with the greatest risk on devices whose web management page is reachable from the WAN/internet. Although no public proof-of-concept is known and no CVSS score is published, CISA added the issue to the Known Exploited Vulnerabilities catalog on 2021-11-03 (confirming in-the-wild exploitation; ransomware use not reported), and the 98th-percentile EPSS of 28.2% indicates an elevated probability of exploitation over the next 30 days.

What to do: Upgrade WF2419 firmware to the latest release from Netis per the vendor's instructions, as required by CISA (no specific fixed firmware version is provided in this data — check with Netis). Disable or restrict WAN-side remote administration so the web management page is not reachable from the internet, and review device logs for signs of exploitation or compromise. Given the KEV listing and 98th-percentile EPSS despite the missing CVSS score, treat this as a high-priority patch for any WF2419 units in service.

Affected
Netis WF2419 router (WF2419 Devices)
Estimated exposure
mass≈1–2 million+ deployed devices worldwide, with likely on the order of 100,000+ internet-exposed (estimate) — The WF2419 is Netis's flagship low-cost router with a very large global installed base — public internet scans and the 2014 Netis/Netcore router worm that infected roughly two million devices indicate millions deployed and well over…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

CISA Known Exploited Vulnerability
Affected
Netis WF2419 Devices
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
netis-systems
Products
wf2419 firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

New Mirai Variant Targeting Network Security Devices

New Mirai botnet variant exploits nine vulnerabilities in SonicWall, D-Link, Netgear, and other devices, with attacks ongoing at publication.

Unit 42 observed attacks exploiting VisualDoor (SonicWall SSL-VPN), CVE-2020-25506 (D-Link DNS-320), CVE-2020-26919 (Netgear ProSAFE Plus), and other flaws, with infrastructure rotating across at least three IP addresses between February 16 and March 13, 2021. Payloads were updated hours after CVE-2021-27561 and CVE-2021-27562 (Yealink Device Management, unauthenticated root RCE) and later added CVE-2021-22502 (Micro Focus Operation Bridge Reporter) and CVE-2019-19356 (Netis WF2419). Successful exploitation invokes wget to fetch shell scripts that download Mirai binaries compiled for multiple architectures and brute-forcers, and attacks were still ongoing when reported.

Palo Alto Unit 42 · 27d agoExploit / PoC in the wildCVE-2020-25506CVE-2020-26919CVE-2019-19356+3 CVEs