CVE-2026-61516
Netis NX10 Credential Disclosure via sysinfo Diagnostic Endpoint
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.
| CWE | CWE-522 |
| Vendor | netis systems |
| Product | nx10 |
| Published | Sep 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for netis systems nx10
Be the first to know when new critical vulnerabilities affecting netis systems nx10 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Netis Systems / NX10
4.0.1.5808 3.0.0.4142
References
hackwithmike.com: https://hackwithmike.com/research/netis/2026-09 hackwithmike.com: https://hackwithmike.com/research/advisories/netis/cve-2026-61516 netis-systems.com: https://www.netis-systems.com/products/NX10.html vulncheck.com: https://www.vulncheck.com/advisories/netis-nx10-credential-disclosure-via-sysinfo-diagnostic-endpoint
Credits
Michael Chan