Netis WF2419 routers contain an operating-system command injection flaw (CWE-78) in the router's web management page that allows an attacker to execute arbitrary commands with root privileges. The flaw is triggered through the web management interface, where crafted input is passed to a system command without adequate sanitization, enabling unauthenticated or low-privilege access to escalate to full command execution as root. An attacker who exploits it gains complete control of the router — root-level code execution — which can be used to intercept or manipulate traffic, pivot into the local network, or enlist the device in a botnet. Any user or organization running a Netis WF2419 router is affected, with the greatest risk on devices whose web management page is reachable from the WAN/internet. Although no public proof-of-concept is known and no CVSS score is published, CISA added the issue to the Known Exploited Vulnerabilities catalog on 2021-11-03 (confirming in-the-wild exploitation; ransomware use not reported), and the 98th-percentile EPSS of 28.2% indicates an elevated probability of exploitation over the next 30 days.
What to do: Upgrade WF2419 firmware to the latest release from Netis per the vendor's instructions, as required by CISA (no specific fixed firmware version is provided in this data — check with Netis). Disable or restrict WAN-side remote administration so the web management page is not reachable from the internet, and review device logs for signs of exploitation or compromise. Given the KEV listing and 98th-percentile EPSS despite the missing CVSS score, treat this as a high-priority patch for any WF2419 units in service.
Affected
Netis WF2419 router (WF2419 Devices)
—
Estimated exposure
mass≈1–2 million+ deployed devices worldwide, with likely on the order of 100,000+ internet-exposed (estimate) — The WF2419 is Netis's flagship low-cost router with a very large global installed base — public internet scans and the 2014 Netis/Netcore router worm that infected roughly two million devices indicate millions deployed and well over…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.
New Mirai botnet variant exploits nine vulnerabilities in SonicWall, D-Link, Netgear, and other devices, with attacks ongoing at publication.
Unit 42 observed attacks exploiting VisualDoor (SonicWall SSL-VPN), CVE-2020-25506 (D-Link DNS-320), CVE-2020-26919 (Netgear ProSAFE Plus), and other flaws, with infrastructure rotating across at least three IP addresses between February 16 and March 13, 2021. Payloads were updated hours after CVE-2021-27561 and CVE-2021-27562 (Yealink Device Management, unauthenticated root RCE) and later added CVE-2021-22502 (Micro Focus Operation Bridge Reporter) and CVE-2019-19356 (Netis WF2419). Successful exploitation invokes wget to fetch shell scripts that download Mirai binaries compiled for multiple architectures and brute-forcers, and attacks were still ongoing when reported.