Impact
An unauthenticated information disclosure flaw in Netis NX10 allows an attacker to query the web management interface’s sysinfo action and obtain the administrator password. The exposed credential can be replayed against the login handler, giving the attacker full administrative control over the device.
Affected Systems
The flaw affects Netis NX10 devices running firmware V4.0.1.5808 and V3.0.0.4142. Only these releases are known to contain the vulnerable sysinfo endpoint.
Risk and Exploitability
The CVSS score of 9.3 indicates an extremely high severity. EPSS data is not available, but the vulnerability does not require special access and can be triggered by any remote user who can reach the device’s web interface. The endpoint is publicly reachable and unauthenticated, making it easy for attackers to obtain the credentials. The device is not listed in the CISA KEV catalog. A likely attack vector is a remote, unauthenticated web request over a network connection.
OpenCVE Enrichment