SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-61516

CRITICAL · CVSS 9.8 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability in Netis NX10 firmware versions 4.0.1.5808 and 3.0.0.4142 allows unauthenticated attackers to access the administrator password through the web management interface, enabling them to gain full administrative access. This critical security flaw poses a significant risk to any organization using affected devices, as it can lead to unauthorized control and manipulation of network settings. Organizations utilizing this firmware should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-61516
Severity
CRITICAL
CVSS
9.8
EPSS
0.38%

Original NVD Description

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.