CRITICAL 9.3 NVD

CVE-2026-61516

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administra

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.

References

Published: 2026-09-08 · Source: NVD · Feed updated: 2026-09-12
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-08 via NVD.

Risk Timeline

CVE Disclosed2026-09-08 · 3 days ago

Remediation Resources

vulnfeed aggregates 12842 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.