Vulnerability index

Browse CVEs

50 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

360r Firmware CRITICAL 9.8
CVE-2023-43134

There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the device wit…

No fix yet
Fix from $2,300 2023-09-20
Wf2409e Firmware CRITICAL 9.8
CVE-2023-42336

An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password …

No fix yet
Fix from $2,300 2023-09-16
Wf2409e Firmware HIGH 8.8
CVE-2023-38829

An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnos…

No fix yet
Fix from $1,950 2023-09-11
Netcore Router Firmware CRITICAL 9.8
CVE-2018-25069

A vulnerability classified as critical has been found in Netis Netcore Router. This affects an unknown part. The manipulation leads to use of hard-co…

No fix yet
Fix from $2,300 2023-01-07
Netcore Router Firmware HIGH 7.5
CVE-2023-0113

A vulnerability was found in Netis Netcore Router up to 2.2.6. It has been declared as problematic. Affected by this vulnerability is an unknown func…

Mitigation only
Fix from $1,950 2023-01-07
Netcore Router Firmware MEDIUM 5.5
CVE-2023-0114

A vulnerability was found in Netis Netcore Router. It has been rated as problematic. Affected by this issue is some unknown functionality of the file…

Mitigation only
Fix from $1,600 2023-01-07
Wf2780 Firmware CRITICAL 9.8
CVE-2021-26747EPSS 54%

Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.

No fix yet
Fix from $2,300 2021-02-18
Wf2471 Firmware HIGH 8.8
CVE-2020-8946

Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/sys_log…

No fix yet
Fix from $1,950 2020-02-12
Wf2419 Firmware HIGH 7.5
CVE-2019-19356 KEVEPSS 28%

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been fo…

Mitigation only
Fix from $1,950 2020-02-07
Dl4343 Firmware HIGH 8.8
CVE-2019-20074

On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.

Mitigation only
Fix from $1,950 2019-12-30
Dl4343 Firmware MEDIUM 6.5
CVE-2019-20071

On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.

No fix yet
Fix from $1,600 2019-12-30
Dl4343 Firmware MEDIUM 6.1
CVE-2019-20070

On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking Configuration).

No fix yet
Fix from $1,600 2019-12-30
Dl4343 Firmware MEDIUM 6.1
CVE-2019-20072

On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration).

No fix yet
Fix from $1,600 2019-12-30
Dl4343 Firmware MEDIUM 6.1
CVE-2019-20073

On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration).

No fix yet
Fix from $1,600 2019-12-30
Dl4343 Firmware MEDIUM 6.1
CVE-2019-20075

On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic).

No fix yet
Fix from $1,600 2019-12-30
Dl4343 Firmware MEDIUM 6.1
CVE-2019-20076

On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configuration).

No fix yet
Fix from $1,600 2019-12-30
Wf2411 Firmware CRITICAL 9.8
CVE-2019-8985EPSS 13%

On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that …

No fix yet
Fix from $2,300 2019-02-21
Wf2419 Firmware HIGH 8.8
CVE-2018-6391

A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete Address Re…

No fix yet
Fix from $1,950 2018-01-29
Wf2419 Firmware MEDIUM 5.4
CVE-2018-5967

Netis WF2419 V2.2.36123 devices allow XSS via the Description parameter on the Bandwidth Control Rule Settings page.

No fix yet
Fix from $1,600 2018-01-25
Wf2419 Firmware MEDIUM 5.4
CVE-2018-6190

Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.

No fix yet
Fix from $1,600 2018-01-24