Authentication Bypass in Netis AC1200 Router by Netis
CVE-2026-36539

Currently unrated

Key Information:

Vendor

Netis

Vendor
CVE Published:
27 May 2026

What is CVE-2026-36539?

The Netis AC1200 Router NC21 version 4.0.1.4296 is vulnerable due to an unsecured CGI endpoint, /cgi-bin/skk_get.cgi, which allows unauthenticated access to the router's complete configuration data. Attackers on the local area network can exploit this vulnerability by sending a simple HTTP GET request, gaining instant access to critical information including administrator credentials, WiFi passwords, PPPoE settings, DDNS credentials, and a comprehensive overview of connected devices. This exposure poses significant risks for users, emphasizing the need for immediate security measures.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.