CRITICAL
9.8 CVE-2026-61516 Published 8 Sept 2026
Netis NX10 Firmware Web Interface Info Disclosure
Worried this affects one of your servers?
Netis NX10 firmware versions 4.0.1.5808 and 3.0.0.4142 contain a vulnerability that allows unauthenticated attackers to retrieve the administrator password.
Exploiting this flaw, attackers can send a request to the 'sysinfo' action in the web management interface without a valid session, exposing the administrator's credentials.
Once the credentials are obtained, attackers can use them to establish a fully authenticated administrator session on the device.
Reference: CVE-2026-61516 on NVD
← Back to Security News