← Back

Wf2411 Firmware

wf2411_firmware

Vendor: Netis Systems • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netis Systems
2Wf2411 Firmware
Wf2780 Firmware
Jun 17, 2026
Feb 18, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
1Netis Systems
2Wf2411 Firmware
Wf2880 Firmware
Jun 17, 2026
Feb 21, 2019
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (devi...Show more
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.Show less