Executive brief
The Netis AC1200 router is a networking device used to provide internet connectivity to homes and small offices. A security flaw allows an unauthenticated person on the local network to take complete control of the router. This could lead to the interception of internet traffic, theft of credentials, or the use of the router as a foothold for further attacks on other connected devices.
Technical details
An unauthenticated command injection vulnerability exists in the Netis AC1200 Router NC21 (firmware V4.0.1.4296) within the /cgi-bin/skk_set.cgi endpoint. The 'password' and 'new_pwd_confirm' POST parameters are passed directly to the underlying OS shell without sanitization. An attacker on the local network can achieve Remote Code Execution (RCE) by sending a specially crafted HTTP POST request containing shell commands wrapped in backticks and encoded in base64. As of the disclosure date, the vendor has not responded to reports and no patch is available.
Affected products
- Netis AC1200 Router NC21 V4.0.1.4296
Timeline
- 2026-02-23: other: Vulnerability discovered
- 2026-02-24: other: Attempted to contact vendor Netis; no response received
- 2026-05-27: advisory: CVE published by NVD/MITRE