Executive brief
The Netis NX10 Wi-Fi 6 router's web management interface discloses the administrator password to unauthenticated attackers through an unprotected API endpoint. An attacker can retrieve the password and immediately use it to establish a fully authenticated administrator session, gaining complete control over the router's configuration and management functions. When combined with a second vulnerability, this enables attackers to execute arbitrary commands as root without requiring any credentials.
Technical details
This is an information disclosure vulnerability caused by improper exposure of sensitive credentials in an unauthenticated API response. The /web/cgi-bin/skk_get.cgi endpoint with the sysinfo action returns the stored administrator password in JSON format without requiring a valid session cookie or authentication. The vulnerable component (CWE-200: Exposure of Sensitive Information; CWE-522: Insufficiently Protected Credentials) fails to separate sensitive credential data from the minimal state information needed by the login page. An unauthenticated attacker with network access to the management interface can request this endpoint over HTTP, extract the plaintext password, and replay it directly to the login handler (/web/cgi-bin/login.cgi) to establish an authenticated administrator session. No patch has been confirmed available from Netis. The vulnerability affects firmware versions V4.0.1.5808 and V3.0.0.4142, with the root cause being design-level credential handling rather than a simple validation bypass.
Affected products
- Netis NX10 V4.0.1.5808, V3.0.0.4142
Timeline
- 2026-09-08: disclosed