Junglewise Threat Intelligence

CVE-2026-61517: Netis NX10 OS command injection in ping diagnostic

CVE-2026-61517 · Severity: high · CVSS 7.2 · Published 2026-09-08

Executive brief

The Netis NX10 router contains a command injection vulnerability in its ping diagnostic feature. An authenticated administrator can inject arbitrary shell commands that execute with root privileges, potentially allowing complete control of the router, including network configuration, traffic monitoring, and access to stored secrets. When chained with a separate credential-disclosure vulnerability, an attacker can achieve unauthenticated root access.

Technical details

The vulnerability is an OS command injection (CWE-78) in the pingHandler function within bin/netis.cgi. The handler processes the IpAddr parameter from requests to /web/cgi-bin/skk_set.cgi and interpolates it directly into a shell command executed via system(). The input filter blocks only four characters (space, pipe, semicolon, ampersand), leaving command-substitution syntax intact. An attacker can exploit this by injecting backticks or ${IFS} variable expansion to bypass the incomplete filter and execute arbitrary commands as root. Authentication as an administrator is required for this vulnerability alone, but can be bypassed when combined with CVE-2026-61516. No vendor fix has been confirmed.

Affected products

  • Netis NX10 V4.0.1.5808 and V3.0.0.4142

Timeline

  • 2026-09-08: disclosed
  • 2026-09-08: advisory: CVE-2026-61517

References

Related threats