CVE-2019-19356 is an authenticated Remote Code Execution (RCE) vulnerability affecting Netis WF2419 routers, specifically firmware versions V1.2.31805 and V2.2.36123. This flaw, rated High severity (CVSS 7.5), allows an authenticated attacker to execute arbitrary system commands as root via the web management page's tracert diagnostic tool due to insufficient input sanitization. The vulnerability is actively exploited in the wild, notably by Mirai variants, and has garnered significant community and media attention, despite no public exploit code being readily available in common databases.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.2.31805CPE matchmatch criteria | cpe:2.3:o:netis-systems:wf2419_firmware:1.2.31805:*:*:*:*:*:*:* | ||
2.2.36123CPE matchmatch criteria | cpe:2.3:o:netis-systems:wf2419_firmware:2.2.36123:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.