Security
Loading…

CVE-2026-61516

CRITICALCVSS 9.8
Description

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.

Timeline
Published:September 8th, 2026 3:18 PM
Last modified:September 8th, 2026 7:56 PM
CVSS Scoring

CVSS v3: 9.8 (CRITICAL)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

Source: NIST NVD · Data may lag official sources by up to one minute