Information Disclosure Vulnerability in Netis E1+ by Netis Systems
CVE-2020-37093
Key Information:
- Vendor
Netis Systems Co., Ltd.
- Status
- Vendor
- CVE Published:
- 3 February 2026
Badges
What is CVE-2020-37093?
The Netis E1+ version 1.2.32533 is subject to an information disclosure vulnerability that permits unauthenticated attackers to extract WiFi credentials, including SSID and passwords, via a specific endpoint. By sending a crafted GET request to the netcore_get.cgi endpoint, attackers can gain unauthorized access to sensitive network information, potentially compromising network security and user privacy. This issue poses a significant risk as it allows attackers easy access to vital credentials without any form of authentication.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Netis E1+ 1.2.32553
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
