<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>NX10 (V4.0.1.5808, V3.0.0.4142) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/nx10-v4.0.1.5808-v3.0.0.4142/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 08 Sep 2026 15:41:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/nx10-v4.0.1.5808-v3.0.0.4142/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Information Disclosure Vulnerability in Netis NX10 Firmware</title><link>https://feed.craftedsignal.io/briefs/2026-09-netis-nx10-info-disclosure/</link><pubDate>Tue, 08 Sep 2026 15:41:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-netis-nx10-info-disclosure/</guid><description>Netis NX10 firmware versions V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability allowing unauthenticated retrieval of administrator credentials via the web management interface.</description><content:encoded><![CDATA[<p>Netis NX10 routers running firmware versions V4.0.1.5808 and V3.0.0.4142 are vulnerable to an unauthenticated information disclosure flaw. The vulnerability resides in the device's web management interface, specifically within the sysinfo action handler. By crafting a specific HTTP request, an unauthenticated attacker can bypass session validation checks and force the device to return sensitive information, including the administrative password in cleartext. This exposure provides attackers with full administrative control over the network device, which can be leveraged to modify firewall rules, intercept traffic, or pivot into the internal network environment. Given the potential for full device compromise and the lack of required authentication, this vulnerability represents a critical risk to infrastructure security.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for full administrative access to the targeted Netis NX10 router. This level of access facilitates persistent unauthorized control, traffic interception, configuration modification, and internal network reconnaissance. The vulnerability impacts residential and small office users deploying these specific firmware versions.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering and security teams:</p>
<ul>
<li>Identify and inventory all Netis NX10 devices across the network environment.</li>
<li>Patch affected devices by upgrading to the latest manufacturer-recommended firmware version, as this vulnerability is exploitable without authentication.</li>
<li>Restrict access to the web management interface of all networking hardware to trusted internal IP ranges only.</li>
<li>Implement monitoring for abnormal HTTP GET requests targeting the '/sysinfo' endpoint in web management traffic logs.</li>
<li>If a patch is unavailable, block access to the administrative web management interface from any untrusted or internet-facing network segments.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category></item></channel></rss>