Netis Systems' vulnerability footprint concentrates in a narrow line of network appliances and firmware, including models such as the WF2880 and N3M series, which occupy a modest but recurring position in vulnerability disclosures. The vendor's disclosures lack a clearly identified recurring weakness pattern, suggesting either diversity in flaw origins or sparse structural commonality across the product portfolio. Defenders tracking this vendor should maintain awareness of firmware update cycles for deployed appliances and treat disclosed issues on their specific product versions; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Netis Systems over time
Signals from CVEs in this vendor scope (51 CVEs).
51 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-22729CRITICAL NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page. | Jan 25, 2024 | 9.8 | 83 | NO | YES |
CVE-2019-19356HIGH Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31 | Feb 7, 2020 | 7.5 | 75 | YES | NO |
CVE-2021-26747CRITICAL Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution. | Feb 18, 2021 | 9.8 | 61 | NO | NO |
CVE-2024-25850CRITICAL Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter | Feb 22, 2024 | 9.8 | 39 | NO | NO |
CVE-2019-8985CRITICAL On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication | Feb 21, 2019 | 9.8 | 31 | NO | NO |
CVE-2023-44860HIGH An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request. | Oct 6, 2023 | 7.5 | 30 | NO | NO |
CVE-2018-25069CRITICAL A vulnerability classified as critical has been found in Netis Netcore Router. This affects an unknown part. The manipulation leads to use of hard-coded password. It is possible to | Jan 7, 2023 | 9.8 | 30 | NO | NO |
CVE-2018-6190MEDIUM Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page. | Jan 24, 2018 | 5.4 | 29 | NO | YES |
CVE-2023-45467CRITICAL Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings. | Oct 13, 2023 | 9.8 | 28 | NO | NO |
CVE-2023-43893CRITICAL Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited v | Oct 2, 2023 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (51 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Netis Systems.
Media articles that mention a CVE ID that affects a product developed by Netis Systems — matched by CVE ID, not by vendor name.