VendorsNetis Systemswf2780all versions
Vulnerabilities

Netis Systems WF2780

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2021-26747
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
Published 2021-02-18 · Modified
10.0EPSS 0.548
CVE-2024-25850
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter
Published 2024-02-22 · Analyzed
9.8EPSS 0.191
CVE-2024-25851
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgitest.cgi.
Published 2024-02-22 · Analyzed
8.0EPSS 0.019
CVE-2025-50635
A null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_0048a728 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling the CONTENT_LENGTH variable, causing the program to crash and potentially leading to a denial-of-service (DoS) attack.
Published 2025-08-13 · Analyzed
7.5EPSS 0.004