Impact
An unauthenticated information disclosure flaw exists in Netis NX10 firmware that allows a remote attacker to send a request to the web interface’s sysinfo action and retrieve the administrator password. The disclosed credential can be replayed against the login handler, enabling the attacker to establish a fully authenticated administrator session on the device. This exposes the system to complete control and potential further exploitation.
Affected Systems
The vulnerability affects Netis Systems NX10 devices running firmware V4.0.1.5808 and V3.0.0.4142. Only these firmware releases are known to contain the flaw; later versions are presumed fixed.
Risk and Exploitability
The CVSS score of 9.3 indicates an extremely high severity. The lack of an EPSS score suggests that the exploitation probability has not been quantified, but the flaw is public knowledge and does not require special privileges or conditions, making it broadly exploitable over a network connection to the web interface. The device is not listed in the CISA KEV catalog, but the accessible endpoint and unmanaged configuration make it a desirable target for attackers seeking to obtain remote administrative control.
OpenCVE Enrichment