CRITICAL 9.8 CVE-2026-61516 Published 8 Sept 2026

Netis NX10 Firmware Web Interface Info Disclosure

Worried this affects one of your servers?

Netis NX10 firmware versions 4.0.1.5808 and 3.0.0.4142 contain a vulnerability that allows unauthenticated attackers to retrieve the administrator password.

Exploiting this flaw, attackers can send a request to the 'sysinfo' action in the web management interface without a valid session, exposing the administrator's credentials.

Once the credentials are obtained, attackers can use them to establish a fully authenticated administrator session on the device.

Reference: CVE-2026-61516 on NVD

← Back to Security News