CVE-2019-19356
Netis WF2419 Devices Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 3 May 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 28.17% probability · 98th percentile
- CISA KEV
- Listed 3 November 2021 · due 3 May 2022
- Weakness
- CWE-78
- Affected
- netis-systems/wf2419 firmware
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-19356
References
- http://packetstormsecurity.com/files/156588/Netis-WF2419-2.2.36123-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/shadowgatt/CVE-2019-19356Exploit, Third Party Advisory
- https://www.digital.security/en/blog/netis-routers-remote-code-execution-cve-2019-19356Exploit, Third Party Advisory
- http://packetstormsecurity.com/files/156588/Netis-WF2419-2.2.36123-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- https://github.com/shadowgatt/CVE-2019-19356Exploit, Third Party Advisory
- https://www.digital.security/en/blog/netis-routers-remote-code-execution-cve-2019-19356Exploit, Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19356US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.