Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-45835

Quick assessment

Affected
n/a n/a
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Netis Systems WF2880是Netis Systems公司的一款双频千兆无线路由器。 Netis Systems WF2880 v2.1.40207版本存在安全漏洞,该漏洞源于cgitest.cgi文件存在空指针取消引用,可能导致拒绝服务。

AI Predicted 5.3 Difficulty: Easy EPSS 0.47% · P39

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-45835

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
A null pointer dereference vulnerability was discovered in Netis WF2880 v2.1.40207. The vulnerability exists in the FUN_004904c8 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the environment variable value CONTENT_LENGTH, causing the program to crash and potentially leading to a denial-of-service (DoS) attack.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Netis Systems WF2880 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Netis Systems WF2880是Netis Systems公司的一款双频千兆无线路由器。 Netis Systems WF2880 v2.1.40207版本存在安全漏洞,该漏洞源于cgitest.cgi文件存在空指针取消引用,可能导致拒绝服务。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2025-45835

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-45835

请登录查看更多情报信息。

Proof of Concept for CVE-2025-45835 (1)

Same Patch Batch · n/a · 2025-05-12 · 15 CVEs total

CVE-2025-22247 6.1 MEDIUM Insecure file handling vulnerability
CVE-2025-26841 WordPress plugin Everest Forms 安全漏洞
CVE-2025-26846 Znuny 安全漏洞
CVE-2024-56523 Radware Cloud Web Application Firewall 安全漏洞
CVE-2024-56524 Radware Cloud Web Application Firewall 安全漏洞
CVE-2025-46611 ARTEC EMA Mail 安全漏洞
CVE-2025-46610 ARTEC EMA Mail 安全漏洞
CVE-2025-44830 engineercms 安全漏洞
CVE-2025-44022 Vvveb 安全漏洞
CVE-2025-45779 Tenda AC10 安全漏洞
CVE-2025-44175 Tenda AC10 安全漏洞
CVE-2025-44176 Tenda FH451 安全漏洞
CVE-2023-34732 Flytxt NEON-dX 安全漏洞
CVE-2024-55466 ThingsBoard 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2025-45835

No comments yet


Leave a comment