Skip to content
Threat Feed
critical advisory

Information Disclosure Vulnerability in Netis NX10 Firmware

Netis NX10 firmware versions V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability allowing unauthenticated retrieval of administrator credentials via the web management interface.

CVE search metadata

CVE search record: CVE-2026-61516. Severity: critical. CVSS: 9.8. KEV: no. Product: NX10 (V4.0.1.5808, V3.0.0.4142). Brief: Information Disclosure Vulnerability in Netis NX10 Firmware. Brief link: https://feed.craftedsignal.io/briefs/2026-09-netis-nx10-info-disclosure/

Netis NX10 routers running firmware versions V4.0.1.5808 and V3.0.0.4142 are vulnerable to an unauthenticated information disclosure flaw. The vulnerability resides in the device's web management interface, specifically within the sysinfo action handler. By crafting a specific HTTP request, an unauthenticated attacker can bypass session validation checks and force the device to return sensitive information, including the administrative password in cleartext. This exposure provides attackers with full administrative control over the network device, which can be leveraged to modify firewall rules, intercept traffic, or pivot into the internal network environment. Given the potential for full device compromise and the lack of required authentication, this vulnerability represents a critical risk to infrastructure security.

Impact

Successful exploitation allows for full administrative access to the targeted Netis NX10 router. This level of access facilitates persistent unauthorized control, traffic interception, configuration modification, and internal network reconnaissance. The vulnerability impacts residential and small office users deploying these specific firmware versions.

Recommendation

Prioritized, concrete actions for detection engineering and security teams:

  • Identify and inventory all Netis NX10 devices across the network environment.
  • Patch affected devices by upgrading to the latest manufacturer-recommended firmware version, as this vulnerability is exploitable without authentication.
  • Restrict access to the web management interface of all networking hardware to trusted internal IP ranges only.
  • Implement monitoring for abnormal HTTP GET requests targeting the '/sysinfo' endpoint in web management traffic logs.
  • If a patch is unavailable, block access to the administrative web management interface from any untrusted or internet-facing network segments.

Immediate actions

Inventory all Netis NX10 devices and initiate firmware update to secure versions

IT Operations 48h

Mitigations

Restrict access to web management interface to trusted internal IP ranges

immediate IT Operations

CVE-2026-61516

Detection coverage 1

Detect CVE-2026-61516 Exploitation - Unauthorized Access to sysinfo

critical

Detects unauthenticated GET requests to the sysinfo endpoint on Netis NX10 web management interfaces, which may indicate exploitation attempts.

sigma tactics: credential_access, initial_access techniques: T1110.001, T1552.001 sources: webserver

Detection queries are available on the platform. Get full rules →