Information Disclosure Vulnerability in Netis NX10 Firmware
Netis NX10 firmware versions V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability allowing unauthenticated retrieval of administrator credentials via the web management interface.
CVE search metadata
CVE search record: CVE-2026-61516. Severity: critical. CVSS: 9.8. KEV: no. Product: NX10 (V4.0.1.5808, V3.0.0.4142). Brief: Information Disclosure Vulnerability in Netis NX10 Firmware. Brief link: https://feed.craftedsignal.io/briefs/2026-09-netis-nx10-info-disclosure/
Netis NX10 routers running firmware versions V4.0.1.5808 and V3.0.0.4142 are vulnerable to an unauthenticated information disclosure flaw. The vulnerability resides in the device's web management interface, specifically within the sysinfo action handler. By crafting a specific HTTP request, an unauthenticated attacker can bypass session validation checks and force the device to return sensitive information, including the administrative password in cleartext. This exposure provides attackers with full administrative control over the network device, which can be leveraged to modify firewall rules, intercept traffic, or pivot into the internal network environment. Given the potential for full device compromise and the lack of required authentication, this vulnerability represents a critical risk to infrastructure security.
Impact
Successful exploitation allows for full administrative access to the targeted Netis NX10 router. This level of access facilitates persistent unauthorized control, traffic interception, configuration modification, and internal network reconnaissance. The vulnerability impacts residential and small office users deploying these specific firmware versions.
Recommendation
Prioritized, concrete actions for detection engineering and security teams:
- Identify and inventory all Netis NX10 devices across the network environment.
- Patch affected devices by upgrading to the latest manufacturer-recommended firmware version, as this vulnerability is exploitable without authentication.
- Restrict access to the web management interface of all networking hardware to trusted internal IP ranges only.
- Implement monitoring for abnormal HTTP GET requests targeting the '/sysinfo' endpoint in web management traffic logs.
- If a patch is unavailable, block access to the administrative web management interface from any untrusted or internet-facing network segments.
Immediate actions
Inventory all Netis NX10 devices and initiate firmware update to secure versions
Mitigations
Restrict access to web management interface to trusted internal IP ranges
CVE-2026-61516
Detection coverage 1
Detect CVE-2026-61516 Exploitation - Unauthorized Access to sysinfo
criticalDetects unauthenticated GET requests to the sysinfo endpoint on Netis NX10 web management interfaces, which may indicate exploitation attempts.
Detection queries are available on the platform. Get full rules →