netis-systems CVE Vulnerabilities & Metrics

Focus on netis-systems vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About netis-systems Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with netis-systems. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total netis-systems CVEs: 32
Earliest CVE date: 24 Jan 2018, 21:29 UTC
Latest CVE date: 25 Jan 2024, 15:15 UTC

Latest CVE reference: CVE-2024-22729

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical netis-systems CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.99

Max CVSS: 10.0

Critical CVEs (≥9): 3

CVSS Range vs. Count

Range Count
0.0-3.9 18
4.0-6.9 9
7.0-8.9 2
9.0-10.0 3

CVSS Distribution Chart

Top 5 Highest CVSS netis-systems CVEs

These are the five CVEs with the highest CVSS scores for netis-systems, sorted by severity first and recency.

All CVEs for netis-systems

CVE-2024-22729 netis-systems vulnerability CVSS: 0 25 Jan 2024, 15:15 UTC

NETIS SYSTEMS MW5360 V1.0.1.3031 was discovered to contain a command injection vulnerability via the password parameter on the login page.

CVE-2023-45468 netis-systems vulnerability CVSS: 0 13 Oct 2023, 13:15 UTC

Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the pingWdogIp. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-45467 netis-systems vulnerability CVSS: 0 13 Oct 2023, 13:15 UTC

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings.

CVE-2023-45466 netis-systems vulnerability CVSS: 0 13 Oct 2023, 13:15 UTC

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the pin_host parameter in the WPS Settings.

CVE-2023-45465 netis-systems vulnerability CVSS: 0 13 Oct 2023, 13:15 UTC

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings.

CVE-2023-45464 netis-systems vulnerability CVSS: 0 13 Oct 2023, 13:15 UTC

Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the servDomain parameter. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-45463 netis-systems vulnerability CVSS: 0 13 Oct 2023, 13:15 UTC

Netis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the hostName parameter in the FUN_0040dabc function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVE-2023-44860 netis-systems vulnerability CVSS: 0 06 Oct 2023, 23:15 UTC

An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request.

CVE-2023-43893 netis-systems vulnerability CVSS: 0 02 Oct 2023, 22:15 UTC

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.

CVE-2023-43892 netis-systems vulnerability CVSS: 0 02 Oct 2023, 22:15 UTC

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerability is exploited via a crafted payload.

CVE-2023-43891 netis-systems vulnerability CVSS: 0 02 Oct 2023, 22:15 UTC

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.

CVE-2023-43890 netis-systems vulnerability CVSS: 0 02 Oct 2023, 20:15 UTC

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via a crafted HTTP request.

CVE-2023-43134 netis-systems vulnerability CVSS: 0 20 Sep 2023, 20:15 UTC

There is an unauthorized access vulnerability in Netis 360RAC1200 v1.3.4517, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.

CVE-2023-42336 netis-systems vulnerability CVSS: 0 16 Sep 2023, 01:15 UTC

An issue in NETIS SYSTEMS WF2409Ev4 v.1.0.1.705 allows a remote attacker to execute arbitrary code and obtain sensitive information via the password parameter in the /etc/shadow.sample component.

CVE-2023-38829 netis-systems vulnerability CVSS: 0 11 Sep 2023, 19:15 UTC

An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnostic tools component in the admin management interface.

CVE-2023-0114 netis-systems vulnerability CVSS: 1.7 07 Jan 2023, 09:15 UTC

A vulnerability was found in Netis Netcore Router. It has been rated as problematic. Affected by this issue is some unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to cleartext storage in a file or on disk. Local access is required to approach this attack. The identifier of this vulnerability is VDB-217592.

CVE-2023-0113 netis-systems vulnerability CVSS: 5.0 07 Jan 2023, 09:15 UTC

A vulnerability was found in Netis Netcore Router up to 2.2.6. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file param.file.tgz of the component Backup Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The associated identifier of this vulnerability is VDB-217591.

CVE-2018-25069 netis-systems vulnerability CVSS: 7.5 07 Jan 2023, 09:15 UTC

A vulnerability classified as critical has been found in Netis Netcore Router. This affects an unknown part. The manipulation leads to use of hard-coded password. It is possible to initiate the attack remotely. The identifier VDB-217593 was assigned to this vulnerability.

CVE-2021-26747 netis-systems vulnerability CVSS: 10.0 18 Feb 2021, 21:15 UTC

Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.

CVE-2020-8946 netis-systems vulnerability CVSS: 9.0 12 Feb 2020, 18:15 UTC

Netis WF2471 v1.2.30142 devices allow an authenticated attacker to execute arbitrary OS commands via shell metacharacters in the /cgi-bin-igd/sys_log_clean.cgi log_3g_type parameter.

CVE-2019-19356 netis-systems vulnerability CVSS: 8.5 07 Feb 2020, 23:15 UTC

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

CVE-2019-20076 netis-systems vulnerability CVSS: 4.3 30 Dec 2019, 00:15 UTC

On Netis DL4323 devices, XSS exists via the form2Ddns.cgi username parameter (DynDns settings of the Dynamic DNS Configuration).

CVE-2019-20075 netis-systems vulnerability CVSS: 4.3 30 Dec 2019, 00:15 UTC

On Netis DL4323 devices, pingrtt_v6.html has XSS (Ping6 Diagnostic).

CVE-2019-20074 netis-systems vulnerability CVSS: 4.0 30 Dec 2019, 00:15 UTC

On Netis DL4323 devices, any user role can view sensitive information, such as a user password or the FTP password, via the form2saveConf.cgi page.

CVE-2019-20073 netis-systems vulnerability CVSS: 4.3 30 Dec 2019, 00:15 UTC

On Netis DL4323 devices, XSS exists via the form2userconfig.cgi username parameter (User Account Configuration).

CVE-2019-20072 netis-systems vulnerability CVSS: 4.3 30 Dec 2019, 00:15 UTC

On Netis DL4323 devices, XSS exists via the form2Ddns.cgi hostname parameter (Dynamic DNS Configuration).

CVE-2019-20071 netis-systems vulnerability CVSS: 5.8 30 Dec 2019, 00:15 UTC

On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.

CVE-2019-20070 netis-systems vulnerability CVSS: 4.3 30 Dec 2019, 00:15 UTC

On Netis DL4323 devices, XSS exists via the urlFQDN parameter to form2url.cgi (aka the Keyword field of the URL Blocking Configuration).

CVE-2019-8985 netis-systems vulnerability CVSS: 9.0 21 Feb 2019, 19:29 UTC

On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.

CVE-2018-6391 netis-systems vulnerability CVSS: 6.8 29 Jan 2018, 19:29 UTC

A cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete Address Reservation List settings.

CVE-2018-5967 netis-systems vulnerability CVSS: 3.5 25 Jan 2018, 08:29 UTC

Netis WF2419 V2.2.36123 devices allow XSS via the Description parameter on the Bandwidth Control Rule Settings page.

CVE-2018-6190 netis-systems vulnerability CVSS: 3.5 24 Jan 2018, 21:29 UTC

Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.