{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nx10-v4.0.1.5808-v3.0.0.4142/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:netis:nx10_firmware:4.0.1.5808:*:*:*:*:*:*:*","cpe:2.3:o:netis:nx10_firmware:3.0.0.4142:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-61516"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NX10 (V4.0.1.5808, V3.0.0.4142)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Netis"],"content_html":"\u003cp\u003eNetis NX10 routers running firmware versions V4.0.1.5808 and V3.0.0.4142 are vulnerable to an unauthenticated information disclosure flaw. The vulnerability resides in the device's web management interface, specifically within the sysinfo action handler. By crafting a specific HTTP request, an unauthenticated attacker can bypass session validation checks and force the device to return sensitive information, including the administrative password in cleartext. This exposure provides attackers with full administrative control over the network device, which can be leveraged to modify firewall rules, intercept traffic, or pivot into the internal network environment. Given the potential for full device compromise and the lack of required authentication, this vulnerability represents a critical risk to infrastructure security.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for full administrative access to the targeted Netis NX10 router. This level of access facilitates persistent unauthorized control, traffic interception, configuration modification, and internal network reconnaissance. The vulnerability impacts residential and small office users deploying these specific firmware versions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify and inventory all Netis NX10 devices across the network environment.\u003c/li\u003e\n\u003cli\u003ePatch affected devices by upgrading to the latest manufacturer-recommended firmware version, as this vulnerability is exploitable without authentication.\u003c/li\u003e\n\u003cli\u003eRestrict access to the web management interface of all networking hardware to trusted internal IP ranges only.\u003c/li\u003e\n\u003cli\u003eImplement monitoring for abnormal HTTP GET requests targeting the '/sysinfo' endpoint in web management traffic logs.\u003c/li\u003e\n\u003cli\u003eIf a patch is unavailable, block access to the administrative web management interface from any untrusted or internet-facing network segments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-08T15:41:23Z","date_published":"2026-09-08T15:41:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-netis-nx10-info-disclosure/","summary":"Netis NX10 firmware versions V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability allowing unauthenticated retrieval of administrator credentials via the web management interface.","title":"Information Disclosure Vulnerability in Netis NX10 Firmware","url":"https://feed.craftedsignal.io/briefs/2026-09-netis-nx10-info-disclosure/"}],"language":"en","title":"CraftedSignal Threat Feed - NX10 (V4.0.1.5808, V3.0.0.4142)","version":"https://jsonfeed.org/version/1.1"}