CVE-2019-8985 is an unauthenticated stack-based buffer overflow vulnerability affecting Netis WF2xxx series routers, including models WF2411 and WF2880. This critical flaw, with a CVSS score of 9.8, can be triggered remotely via a specially crafted HTTP GET request containing an overly long "Authorization: Basic" header. Successful exploitation can lead to denial of service (device restart) or, more severely, remote code execution. While the vulnerability has a high EPSS score indicating significant potential impact, there is currently no evidence of active exploitation, public exploit code, or community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.1.36123CPE matchmatch criteria | cpe:2.3:o:netis-systems:wf2411_firmware:2.1.36123:*:*:*:*:*:*:* | ||
2.1.36123CPE matchmatch criteria | cpe:2.3:o:netis-systems:wf2880_firmware:2.1.36123:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.