Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 30 May 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netis
Netis ac1200 Router |
|
| Vendors & Products |
Netis
Netis ac1200 Router |
Thu, 28 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Retrieval of Router Configuration via Unprotected CGI Endpoint |
Thu, 28 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Wed, 27 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthorized Retrieval of Router Configuration via Unprotected CGI Endpoint | |
| Weaknesses | CWE-200 |
Wed, 27 May 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netis AC1200 Router NC21 V4.0.1.4296 exposes a CGI endpoint /cgi-bin/skk_get.cgi that returns the entire router configuration as a JSON response with no authentication required. Any attacker on the LAN can send a single HTTP GET request and instantly retrieve administrator credentials, WiFi passwords, PPPoE credentials, DDNS credentials, and a full map of all connected devices. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-28T13:36:27.542Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36539
Updated: 2026-05-28T13:36:22.583Z
Status : Deferred
Published: 2026-05-27T14:16:45.527
Modified: 2026-06-17T10:41:08.397
Link: CVE-2026-36539
No data.
OpenCVE Enrichment
Updated: 2026-05-30T21:22:38Z