Unauthenticated Command Injection in Netis AC1200 Router
CVE-2026-36540

7.3HIGH

Key Information:

Vendor

Netis

Vendor
CVE Published:
27 May 2026

What is CVE-2026-36540?

The Netis AC1200 Router NC21 V4.0.1.4296 has a serious vulnerability that allows unauthorized users to exploit the /cgi-bin/skk_set.cgi endpoint. This vulnerability permits an attacker to perform command injection due to the absence of input validation on the password and new_pwd_confirm parameters. The flaw enables remote code execution via a single unauthenticated HTTP POST request, exposing the router to significant security risks. Attackers can execute arbitrary shell commands, compromising the integrity of the device and potentially gaining control over the network.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.