VulnerabilityModified
CVE-2021-26747
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
CRITICAL 9.8EPSS 54.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 54.8%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 54.78% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- netis-systems/wf2780 firmware · netis-systems/wf2411 firmware
- Source
- cve@mitre.org
References
- http://www.netis-systems.com.tw/Product, Vendor Advisory
- https://github.com/yhstar00/netis-routeExploit, Third Party Advisory
- http://www.netis-systems.com.tw/Product, Vendor Advisory
- https://github.com/yhstar00/netis-routeExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.