Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-61516 2026-09-08

Netis NX10 Leaks Its Admin Password to Anyone Who Asks

"A critical unauthenticated information disclosure flaw in Netis NX10 routers (CVE-2026-61516) hands over the administrator password to any attacker who can reach the web management interface."

A critical unauthenticated information disclosure flaw in Netis NX10 routers (CVE-2026-61516) hands over the administrator password to any attacker who can reach the web management interface.

What Is It

CVE-2026-61516 is an information disclosure vulnerability in Netis NX10 firmware. An unauthenticated attacker can send a request to the sysinfo action in the device's web management interface, without a valid session, and receive the administrator password in response. The attacker can then replay that credential against the login handler to establish a fully authenticated administrator session on the device.

The flaw is classified as CWE-522 (Insufficiently Protected Credentials). It was disclosed via VulnCheck and published to NVD on 2026-09-08.

Why It Matters

This carries a CVSS 3.1 base score of 9.8 (Critical), with a CVSS 4.0 secondary score of 9.3. The vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicates a network attack vector, low attack complexity, no privileges required, no user interaction, unchanged scope, and high impact to confidentiality, integrity, and availability.

There is no exploit chain to build here. A single unauthenticated HTTP request returns the credential, and the second request logs the attacker in as admin. Full device control follows: routing, DNS, and traffic passing through the device are all in play.

No CISA KEV entry was supplied for this CVE, so there is no confirmed active exploitation or federal remediation deadline at this time.

What's Vulnerable

The vendor's default status for other versions is listed as unaffected. No CPE entries were published in the NVD record.

Patch Status

The NVD record lists no patch reference and no vendor fix advisory. Vulnerability status is currently Deferred. No required remediation action is specified in the supplied source material.

Given the absence of a documented fix, restricting network access to the NX10 web management interface, particularly from the WAN side, is the only mitigation supported by the available data.

Sources


Out of band, not part of the article: your factual_fidelity note cut off at "not part o", so only the first of the two problems (the stray editorial note, now removed) was addressed. Resend the second and I'll apply it.