CVE-2021-26747
Published Feb 18, 2021Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
Vendor/product archive
2 CVEs tagged to netis-systems / wf2411_firmware — 2 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authenticatio…