Loading
Generated remediation guidance and an executive summary. No account required.
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.
Use CWE-78, Netis-Systems vendor hub and Wf2419 Firmware product page to widen CVE-2019-19356 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2018-6391, CVE-2018-5967 and CVE-2018-6190 for nearby disclosures in the same product family.