A critical unauthenticated information disclosure flaw in Netis NX10 routers (CVE-2026-61516) hands over the administrator password to any attacker who can reach the web management interface.
What Is It
CVE-2026-61516 is an information disclosure vulnerability in Netis NX10 firmware. An unauthenticated attacker can send a request to the sysinfo action in the device's web management interface, without a valid session, and receive the administrator password in response. The attacker can then replay that credential against the login handler to establish a fully authenticated administrator session on the device.
The flaw is classified as CWE-522 (Insufficiently Protected Credentials). It was disclosed via VulnCheck and published to NVD on 2026-09-08.
Why It Matters
This carries a CVSS 3.1 base score of 9.8 (Critical), with a CVSS 4.0 secondary score of 9.3. The vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicates a network attack vector, low attack complexity, no privileges required, no user interaction, unchanged scope, and high impact to confidentiality, integrity, and availability.
There is no exploit chain to build here. A single unauthenticated HTTP request returns the credential, and the second request logs the attacker in as admin. Full device control follows: routing, DNS, and traffic passing through the device are all in play.
No CISA KEV entry was supplied for this CVE, so there is no confirmed active exploitation or federal remediation deadline at this time.
What's Vulnerable
- Vendor: Netis Systems
- Product: NX10
- Affected firmware: V4.0.1.5808 and V3.0.0.4142
The vendor's default status for other versions is listed as unaffected. No CPE entries were published in the NVD record.
Patch Status
The NVD record lists no patch reference and no vendor fix advisory. Vulnerability status is currently Deferred. No required remediation action is specified in the supplied source material.
Given the absence of a documented fix, restricting network access to the NX10 web management interface, particularly from the WAN side, is the only mitigation supported by the available data.
Sources
- NVD, CVE-2026-61516
- VulnCheck Advisory; Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint
- Hack With Mike; CVE-2026-61516 Advisory
- Hack With Mike; Netis Research, September 2026
- Netis Systems; NX10 Product Page
Out of band, not part of the article: your factual_fidelity note cut off at "not part o", so only the first of the two problems (the stray editorial note, now removed) was addressed. Resend the second and I'll apply it.