Junglewise Threat Intelligence

CVE-2026-36539: Netis AC1200 Router NC21 unauthenticated information disclosure in skk_get.cgi

CVE-2026-36539 · Severity: info · CVSS 8.8 · Published 2026-05-27

Technologies: Netis Systems AC1200 Router NC21. Vendors: Netis Systems.

Executive brief

The Netis AC1200 Router NC21 contains a security flaw that allows anyone on the local network to access the device's full configuration without a password. This includes the exposure of administrator credentials, Wi-Fi passwords, and internet connection details. An attacker could use this information to take complete control of the router, monitor network traffic, or gain access to other devices in the home or office.

Technical details

The Netis AC1200 Router NC21 running firmware V4.0.1.4296 contains an unauthenticated information disclosure vulnerability in the /cgi-bin/skk_get.cgi endpoint. An attacker on the local area network (LAN) can trigger this vulnerability by sending a simple HTTP GET request to the affected endpoint. The server responds with a JSON object containing the complete device configuration, including administrator passwords, Wi-Fi PSKs, PPPoE credentials, and DDNS credentials. While these sensitive values are Base64-encoded, they are not encrypted and can be trivially decoded. As of the disclosure date, the vendor has not released a patch.

Affected products

  • Netis Systems AC1200 Router NC21 V4.0.1.4296

Timeline

  • 2026-05-27: disclosed: Vulnerability disclosed via GitHub and NVD
  • 2026-05-27: advisory

References

Related threats