Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-61516— Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint

Quick assessment

Affected
Netis Systems NX10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Netis NX10 固件版本 V4.0.1.5808 和 V3.0.0.4142 存在信息泄露漏洞,允许未认证的发送请求到Web管理界面的 sysinfo 操作以获取管理员密码,且无需有效的会话。攻击者可以利用暴露的凭据向登录处理程序重放请求,从而在设备上建立一个完全认证的管理员会话。

CVSS 9.8 · Critical

Affected Version Matrix 2

VendorProduct Version RangeStatus
Netis Systems NX10 4.0.1.5808 affected
3.0.0.4142 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-61516

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint
Source: CVE Program / CVE List V5
Vulnerability Description
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不充分的凭证保护机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Netis Systems NX10 4.0.1.5808 -

II. Public POCs for CVE-2026-61516

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-61516

登录查看更多情报信息。

Vendor Advisories for CVE-2026-61516 (2)

Security Blog Posts for CVE-2026-61516 (1)

Vendor Pages for CVE-2026-61516 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-61516

No comments yet


Leave a comment