« Back to list

Netis-systems

Netis-systems Wf2780 Firmware: vulnerabilities and CVEs

Netis-systems Wf2780 Firmware has 4 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs4
Last 12 months0
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-50635High (7.5)0.40%—Aug 13, 2025
A null pointer dereference vulnerability was discovered in Netis WF2780 v2.2.35445. The vulnerability exists in the FUN_0048a728 function of the cgitest.cgi file. Attackers can trigger this vulnerability by controlling…
CVE-2024-25851High (8)1.9%—Feb 22, 2024
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the config_sequence parameter in other_para of cgitest.cgi.
CVE-2024-25850Critical (9.8)19%—Feb 22, 2024
Netis WF2780 v2.1.40144 was discovered to contain a command injection vulnerability via the wps_ap_ssid5g parameter
CVE-2021-26747Critical (9.8)55%—Feb 18, 2021
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1190 Exploit Public-Facing Application1
  2. T1499 Endpoint Denial of Service1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Netis-systems