PT-2024-10066 · Netis · Netis Wifi 11Ac Router Nc63+4

Published

2024-12-27

·

Updated

2025-01-08

·

CVE-2024-48455

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Netis Wifi6 Router NX10 versions 2.0.1.3643 through 2.0.1.3582 Netis Wifi 11AC Router NC65 version 3.0.0.3749 Netis Wifi 11AC Router NC63 versions 3.0.0.3327 through 3.0.0.3503 Netis Wifi 11AC Router NC21 versions 3.0.0.3800 through 3.0.0.3329 Netis Wifi Router MW5360 versions 1.0.1.3442 through 1.0.1.3031
Description The issue is related to insufficient protection of service data in the web interface of Netis Wi-Fi routers. This allows a remote attacker to obtain sensitive information via the mode name and wl link parameters of the skk get.cgi component. There is no information about the estimated number of potentially affected devices or real-world incidents where this issue was exploited.
Recommendations For Netis Wifi6 Router NX10 versions 2.0.1.3643 and 2.0.1.3582, consider disabling the skk get.cgi component until a patch is available. For Netis Wifi 11AC Router NC65 version 3.0.0.3749, restrict access to the skk get.cgi component to minimize the risk of exploitation. For Netis Wifi 11AC Router NC63 versions 3.0.0.3327 through 3.0.0.3503, avoid using the mode name and wl link parameters in the affected API endpoint until the issue is resolved. For Netis Wifi 11AC Router NC21 versions 3.0.0.3800 through 3.0.0.3329, consider temporarily disabling the skk get.cgi component until a patch is available. For Netis Wifi Router MW5360 versions 1.0.1.3442 through 1.0.1.3031, restrict access to the vulnerable module to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00204
CVE-2024-48455

Affected Products

Netis Wifi 11Ac Router Nc21
Netis Wifi 11Ac Router Nc63
Netis Wifi 11Ac Router Nc65
Netis Wifi Router Mw5360
Netis Wifi6 Router Nx10