EIP-2026-101889
PRE-CVENetis WF2419 2.2.36123 - Remote Code Execution
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-101889. PoCs published by Elias Issa.
AI-analyzed exploit summary This exploit leverages a command injection vulnerability in Netis WF2419 routers by sending a crafted POST request to the `netcore_set.cgi` endpoint, allowing remote code execution. The payload injects commands via the `tools_ip_url` parameter, and the results are retrieved from `netcore_get.cgi`.
Description
Netis WF2419 2.2.36123 - Remote Code Execution
Exploits (1)
This exploit leverages a command injection vulnerability in Netis WF2419 routers by sending a crafted POST request to the `netcore_set.cgi` endpoint, allowing remote code execution. The payload injects commands via the `tools_ip_url` parameter, and the results are retrieved from `netcore_get.cgi`.