EIP-2026-101889

PRE-CVE

Netis WF2419 2.2.36123 - Remote Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-101889. PoCs published by Elias Issa.

AI-analyzed exploit summary This exploit leverages a command injection vulnerability in Netis WF2419 routers by sending a crafted POST request to the `netcore_set.cgi` endpoint, allowing remote code execution. The payload injects commands via the `tools_ip_url` parameter, and the results are retrieved from `netcore_get.cgi`.

Description

Netis WF2419 2.2.36123 - Remote Code Execution

Exploits (1)

exploitdb WORKING POC
by Elias Issa · pythonwebappshardware
https://www.exploit-db.com/exploits/48149

This exploit leverages a command injection vulnerability in Netis WF2419 routers by sending a crafted POST request to the `netcore_set.cgi` endpoint, allowing remote code execution. The payload injects commands via the `tools_ip_url` parameter, and the results are retrieved from `netcore_get.cgi`.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Netis WF2419 V2.2.36123
Auth required
Prerequisites: Network access to the target device · Valid admin credentials (if authentication is enforced)
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026