Executive brief
Netis WF2419 routers are vulnerable to authenticated remote code execution as root via the web management interface. The flaw exists in the tracert diagnostic tool due to insufficient sanitization of user input, allowing for OS command injection.
Affected products
- Netis Systems WF2419 firmware V1.2.31805, V2.2.36123
Timeline
- 2020-02-07: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild per CISA KEV catalog