ZeroHour

CVE-2026-61516

large

Unauthenticated admin password disclosure in Netis NX10 router firmware

CVSS 4.0
9.3 critical
EPSS
<1%p32
Published
()
Modified
AI analysis

Netis NX10 router firmware versions V4.0.1.5808 and V3.0.0.4142 fail to adequately protect the administrator password (CWE-522), allowing it to be retrieved through the sysinfo action of the device's web management interface. An unauthenticated attacker can trigger the disclosure with a single request to that action, and no valid session or credentials are required. Because the response returns the administrator password, the attacker can replay it against the login handler to establish a fully authenticated administrator session and take complete control of the router's configuration and network settings. Any Netis NX10 running either of the affected firmware builds is exposed, with the greatest risk on devices whose management interface is reachable from untrusted networks such as the WAN or the internet. Exploitation has not yet been observed: no public proof-of-concept is known, the issue is not in CISA's KEV, and EPSS estimates the 30-day exploitation probability at only 0.4%.

What to do: Upgrade affected NX10 units to the latest firmware from Netis as soon as a fixed build is released (no fixed version is named in the advisory), and change the administrator password afterward. Until patched, disable remote/WAN access to the web management interface or restrict it to trusted networks with firewall rules, and check whether the admin UI is currently reachable from the internet.

Affected
Netis NX10 router firmwareV4.0.1.5808 and V3.0.0.4142
Estimated exposure
large≈10,000–100,000 internet-exposed devices (estimate; total installed base likely larger) — netis is a widely distributed budget consumer router brand and WAN-reachable router web interfaces of this type routinely appear in public internet scans in the tens of thousands, so exposure is estimated at that order of magnitude while…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.

Weakness
CWE-522
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.