Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netis-systems
Netis-systems nx10 |
|
| Vendors & Products |
Netis-systems
Netis-systems nx10 |
Tue, 08 Sep 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device. | |
| Title | Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint | |
| Weaknesses | CWE-522 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-08T14:23:57.088Z
Reserved: 2026-07-10T15:43:36.627Z
Link: CVE-2026-61516
No data.
Status : Deferred
Published: 2026-09-08T15:18:44.170
Modified: 2026-09-08T19:56:50.950
Link: CVE-2026-61516
No data.
OpenCVE Enrichment
Updated: 2026-09-08T20:34:59Z
Weaknesses