Netis Systems
netis-systems
51 CVEs • 27 products
Products (27)
Click to collapseToggle
Products (27)
Click to collapse
CVEs (51)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Netis Systems 1Dl4343 Firmware Jun 17, 2026 Dec 30, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configuration). |
1Netis Systems 1Dl4343 Firmware Jun 17, 2026 Dec 30, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic). |
1Netis Systems 1Dl4343 Firmware Jun 17, 2026 Dec 30, 2019 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page. |
1Netis Systems 1Dl4343 Firmware Jun 17, 2026 Dec 30, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration). |
1Netis Systems 1Dl4343 Firmware Jun 17, 2026 Dec 30, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration). |
1Netis Systems 1Dl4343 Firmware Jun 17, 2026 Dec 30, 2019 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs. |
1Netis Systems 1Dl4343 Firmware Jun 17, 2026 Dec 30, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking Configuration). |
1Netis Systems 2Wf2411 Firmware Wf2880 FirmwareJun 17, 2026 Feb 21, 2019 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (devi...Show more |
1Netis Systems 1Wf2419 Firmware Jun 17, 2026 Jan 29, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete Address Reservation List settings. |
Netis WF2419 V2.2.36123 devices allow XSS via the Description parameter on the Bandwidth Control Rule Settings page. |
Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page. |