CVE-2026-61516
9.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Summary
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Netis Systems | NX10 | 4.0.1.5808 | affected |
| Netis Systems | NX10 | 3.0.0.4142 | affected |
Weaknesses
- CWE-522: Insufficiently Protected Credentials
References
- https://hackwithmike.com/research/netis/2026-09
- https://hackwithmike.com/research/advisories/netis/cve-2026-61516
- https://www.netis-systems.com/products/NX10.html
- https://www.vulncheck.com/advisories/netis-nx10-credential-disclosure-via-sysinfo-diagnostic-endpoint
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.