Junglewise Threat Intelligence

CVE-2026-36540: Netis AC1200 Router command injection in skk_set.cgi

CVE-2026-36540 · Severity: info · CVSS 8.8 · Published 2026-05-27

Technologies: Netis Systems AC1200 Router NC21. Vendors: Netis Systems.

Executive brief

The Netis AC1200 router is a networking device used to provide internet connectivity to homes and small offices. A security flaw allows an unauthenticated person on the local network to take complete control of the router. This could lead to the interception of internet traffic, theft of credentials, or the use of the router as a foothold for further attacks on other connected devices.

Technical details

An unauthenticated command injection vulnerability exists in the Netis AC1200 Router NC21 (firmware V4.0.1.4296) within the /cgi-bin/skk_set.cgi endpoint. The 'password' and 'new_pwd_confirm' POST parameters are passed directly to the underlying OS shell without sanitization. An attacker on the local network can achieve Remote Code Execution (RCE) by sending a specially crafted HTTP POST request containing shell commands wrapped in backticks and encoded in base64. As of the disclosure date, the vendor has not responded to reports and no patch is available.

Affected products

  • Netis AC1200 Router NC21 V4.0.1.4296

Timeline

  • 2026-02-23: other: Vulnerability discovered
  • 2026-02-24: other: Attempted to contact vendor Netis; no response received
  • 2026-05-27: advisory: CVE published by NVD/MITRE

References

Related threats