peter bassill · operator
$ cve CVE-2019-19356 JSON

CVE-2019-19356 KEV

7.5
HIGH · CVSS 3.1 · EPSS 28.2% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2022-05-03.

Description

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS28.17% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2022-05-03
Public exploitnone known
Published2020-02-07
Last modified2026-06-17

CISA KEV

NameNetis WF2419 Devices Remote Code Execution Vulnerability
Added2021-11-03
Due2022-05-03
Vendor / productNetis / WF2419 Devices
Ransomware usenone reported

Affected (2)

VendorProduct
netis-systemswf2419
netis-systemswf2419 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD