Executive brief
The Netis AC1200 router contains a pre-configured administrative password that is identical for all affected devices. This allows an attacker who can reach the device's login interface to take complete control of the router. Once in control, an attacker could monitor internet traffic, redirect users to malicious websites, or disable the network entirely.
Technical details
The Netis AC1200 Router NC21 (firmware V4.0.1.4296) contains a hard-coded root credential within the /etc/shadow.sample file. The root account is configured with the trivially weak password 'root'. An attacker with network access to the device's management services (such as SSH) can use these credentials to authenticate without authorization. Successful exploitation grants the attacker full root-level access to the underlying Linux operating system, enabling complete device compromise. As of the disclosure date, the vendor has not responded to reports, and no patch is available.
Affected products
- Netis AC1200 Router NC21 V4.0.1.4296
Timeline
- 2026-02-23: other: Vulnerability discovered
- 2026-02-24: other: Attempted to contact vendor Netis; no response received
- 2026-05-06: other: CVE assigned
- 2026-05-27: advisory: NVD publication date