Description
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.
Published: 2026-09-08
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Credential disclosure leading to full administrative access
Action: Patch firmware
AI Analysis

Impact

An unauthenticated information disclosure flaw in Netis NX10 allows an attacker to query the web management interface’s sysinfo action and obtain the administrator password. The exposed credential can be replayed against the login handler, giving the attacker full administrative control over the device.

Affected Systems

The flaw affects Netis NX10 devices running firmware V4.0.1.5808 and V3.0.0.4142. Only these releases are known to contain the vulnerable sysinfo endpoint.

Risk and Exploitability

The CVSS score of 9.3 indicates an extremely high severity. EPSS data is not available, but the vulnerability does not require special access and can be triggered by any remote user who can reach the device’s web interface. The endpoint is publicly reachable and unauthenticated, making it easy for attackers to obtain the credentials. The device is not listed in the CISA KEV catalog. A likely attack vector is a remote, unauthenticated web request over a network connection.

Generated by OpenCVE AI on September 8, 2026 at 16:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Netis NX10 firmware to a release that removes the vulnerable sysinfo endpoint
  • Restrict the web management interface to trusted IP ranges or block it behind a firewall or ACL
  • Change the default or long‑standing administrator password and enforce a strong password policy

Generated by OpenCVE AI on September 8, 2026 at 16:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Netis-systems
Netis-systems nx10
Vendors & Products Netis-systems
Netis-systems nx10

Tue, 08 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.
Title Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint
Weaknesses CWE-522
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Netis-systems Nx10
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-19T14:21:56.819Z

Reserved: 2026-07-10T15:43:36.627Z

Link: CVE-2026-61516

cve-icon Vulnrichment

Updated: 2026-09-19T14:20:11.785Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T15:18:44.170

Modified: 2026-09-19T15:16:59.777

Link: CVE-2026-61516

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:34:59Z

Weaknesses
  • CWE-522

    Insufficiently Protected Credentials