← Back to CVE List
Vulnerability Intelligence Report
Netis WF2419 Devices Remote Code Execution Vulnerability

CVE-2019-19356

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.5
HIGH
Exploitability:1.7
Impact Score:5.9
EPSS Probability:27.96%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-78 ↗CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Affected Products & Versions

Vendor Product Affected Versions
netis-systems wf2419_firmware 1.2.31805, 2.2.36123
netis-systems wf2419 all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
27.962%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-11-27T00:00:00
Published2020-02-07T22:49:07
Patch Date2020-02-04
Last Updated2025-10-21T23:35:51

LINK COPIED TO CLIPBOARD