← Back

Netis Systems

netis-systems

51 CVEs • 27 products

Products (27)

Click to collapse
Toggle
N3m Firmware
n3m_firmware
360r Firmware
360r_firmware
N3mv2 Firmware
n3mv2_firmware
Wf2419
wf2419
Wf2411
wf2411
Wf2880
wf2880
Dl4343
dl4343
Wf2471
wf2471
Wf2780
wf2780
Wf2409e
wf2409e
360r
N3m
n3m
Mw5360
mw5360
Mex605
mex605
Netis Wf 2404
netis_wf-2404

CVEs (51)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netis Systems
1Dl4343 Firmware
Jun 17, 2026
Dec 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configuration).
1Netis Systems
1Dl4343 Firmware
Jun 17, 2026
Dec 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic).
1Netis Systems
1Dl4343 Firmware
Jun 17, 2026
Dec 30, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.
1Netis Systems
1Dl4343 Firmware
Jun 17, 2026
Dec 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration).
1Netis Systems
1Dl4343 Firmware
Jun 17, 2026
Dec 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration).
1Netis Systems
1Dl4343 Firmware
Jun 17, 2026
Dec 30, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.
1Netis Systems
1Dl4343 Firmware
Jun 17, 2026
Dec 30, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking Configuration).
1Netis Systems
2Wf2411 Firmware
Wf2880 Firmware
Jun 17, 2026
Feb 21, 2019
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (devi...Show more
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.Show less
1Netis Systems
1Wf2419 Firmware
Jun 17, 2026
Jan 29, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete Address Reservation List settings.
1Netis Systems
1Wf2419 Firmware
Jun 17, 2026
Jan 25, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Netis WF2419 V2.2.36123 devices allow XSS via the Description parameter on the Bandwidth Control Rule Settings page.
1Netis Systems
1Wf2419 Firmware
Jun 17, 2026
Jan 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.