Vulnerabilities
Vulnerable Software
Netis-Systems:  >> Wf2780 Firmware  Security Vulnerabilities
A null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_0048a728 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the CONTENT_LENGTH variable, causing the program to crash and potentially leading to a denial-of-service (DoS) attack.
CVSS Score
7.5
EPSS Score
0.001
Published
2025-08-13
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter
CVSS Score
9.8
EPSS Score
0.105
Published
2024-02-22
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgitest.cgi.
CVSS Score
8.0
EPSS Score
0.004
Published
2024-02-22
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
CVSS Score
9.8
EPSS Score
0.244
Published
2021-02-18


Contact Us

Shodan ® - All rights reserved