Vulnerabilities
Vulnerable Software
Netis-Systems:  >> Wf2411  Security Vulnerabilities
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
CVSS Score
9.8
EPSS Score
0.244
Published
2021-02-18
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.
CVSS Score
9.8
EPSS Score
0.718
Published
2019-02-21


Contact Us

Shodan ® - All rights reserved