Description
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.
Published: 2026-09-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated information disclosure flaw exists in Netis NX10 firmware that allows a remote attacker to send a request to the web interface’s sysinfo action and retrieve the administrator password. The disclosed credential can be replayed against the login handler, enabling the attacker to establish a fully authenticated administrator session on the device. This exposes the system to complete control and potential further exploitation.

Affected Systems

The vulnerability affects Netis Systems NX10 devices running firmware V4.0.1.5808 and V3.0.0.4142. Only these firmware releases are known to contain the flaw; later versions are presumed fixed.

Risk and Exploitability

The CVSS score of 9.3 indicates an extremely high severity. The lack of an EPSS score suggests that the exploitation probability has not been quantified, but the flaw is public knowledge and does not require special privileges or conditions, making it broadly exploitable over a network connection to the web interface. The device is not listed in the CISA KEV catalog, but the accessible endpoint and unmanaged configuration make it a desirable target for attackers seeking to obtain remote administrative control.

Generated by OpenCVE AI on September 8, 2026 at 15:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Netis NX10 firmware to the latest version that no longer contains the vulnerable sysinfo endpoint
  • Restrict network access to the device’s web management interface with firewall or ACL rules, limiting it to trusted IP addresses
  • Change the default or long‑standing administrator password and enforce strong password policies
  • If the firmware upgrade is not immediately possible, disable or block the sysinfo endpoint via web server configuration or security device

Generated by OpenCVE AI on September 8, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.
Title Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-08T14:23:57.088Z

Reserved: 2026-07-10T15:43:36.627Z

Link: CVE-2026-61516

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T15:18:44.170

Modified: 2026-09-08T15:18:44.170

Link: CVE-2026-61516

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:30:18Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials