Executive brief
The Netis AC1200 Router NC21 contains a security flaw that allows anyone on the local network to access the device's full configuration without a password. This includes the exposure of administrator credentials, Wi-Fi passwords, and internet connection details. An attacker could use this information to take complete control of the router, monitor network traffic, or gain access to other devices in the home or office.
Technical details
The Netis AC1200 Router NC21 running firmware V4.0.1.4296 contains an unauthenticated information disclosure vulnerability in the /cgi-bin/skk_get.cgi endpoint. An attacker on the local area network (LAN) can trigger this vulnerability by sending a simple HTTP GET request to the affected endpoint. The server responds with a JSON object containing the complete device configuration, including administrator passwords, Wi-Fi PSKs, PPPoE credentials, and DDNS credentials. While these sensitive values are Base64-encoded, they are not encrypted and can be trivially decoded. As of the disclosure date, the vendor has not released a patch.
Affected products
- Netis Systems AC1200 Router NC21 V4.0.1.4296
Timeline
- 2026-05-27: disclosed: Vulnerability disclosed via GitHub and NVD
- 2026-05-27: advisory