Command Injection Vulnerability in Netis WF2780
CVE-2024-25850

Currently unrated

Key Information:

Vendor

Netis

Vendor
CVE Published:
22 February 2024

What is CVE-2024-25850?

The Netis WF2780 router, specifically version 2.1.40144, has been identified as having a command injection vulnerability that can be exploited through the 'wps_ap_ssid5g' parameter. This flaw allows an attacker to inject arbitrary commands into the system, potentially leading to unauthorized access and control of the device. Users are encouraged to be vigilant and update their firmware to mitigate the risks associated with this vulnerability. Network security could be compromised, emphasizing the necessity for regular software updates and security assessments.

References

EPSS Score

10% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.