CVE-2026-61516
largeUnauthenticated admin password disclosure in Netis NX10 router firmware
Netis NX10 router firmware versions V4.0.1.5808 and V3.0.0.4142 fail to adequately protect the administrator password (CWE-522), allowing it to be retrieved through the sysinfo action of the device's web management interface. An unauthenticated attacker can trigger the disclosure with a single request to that action, and no valid session or credentials are required. Because the response returns the administrator password, the attacker can replay it against the login handler to establish a fully authenticated administrator session and take complete control of the router's configuration and network settings. Any Netis NX10 running either of the affected firmware builds is exposed, with the greatest risk on devices whose management interface is reachable from untrusted networks such as the WAN or the internet. Exploitation has not yet been observed: no public proof-of-concept is known, the issue is not in CISA's KEV, and EPSS estimates the 30-day exploitation probability at only 0.4%.
What to do: Upgrade affected NX10 units to the latest firmware from Netis as soon as a fixed build is released (no fixed version is named in the advisory), and change the administrator password afterward. Until patched, disable remote/WAN access to the web management interface or restrict it to trusted networks with firewall rules, and check whether the admin UI is currently reachable from the internet.
| Netis NX10 router firmware | V4.0.1.5808 and V3.0.0.4142 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.
- Weakness
- CWE-522
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.