CVE-2026-61517
Netis NX10 OS Command Injection via Ping Diagnostic Handler
CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command injection vulnerability in the ping diagnostic handler that allows authenticated administrators to execute arbitrary shell commands as root by injecting into the IpAddr parameter. The parameter is interpolated directly into a shell command executed through system() with an incomplete denylist that only blocks spaces, pipes, semicolons, and ampersands, leaving command substitution and alternate field separator expansion available for exploitation.
| CWE | CWE-78 |
| Vendor | netis systems |
| Product | nx10 |
| Published | Sep 8, 2026 |
| Last Updated | Sep 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for netis systems nx10
Be the first to know when new high vulnerabilities affecting netis systems nx10 are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Netis Systems / NX10
4.0.1.5808 3.0.0.4142
References
hackwithmike.com: https://hackwithmike.com/research/netis/2026-09 hackwithmike.com: https://hackwithmike.com/research/advisories/netis/cve-2026-61517 netis-systems.com: https://www.netis-systems.com/products/NX10.html vulncheck.com: https://www.vulncheck.com/advisories/netis-nx10-os-command-injection-via-ping-diagnostic-handler
Credits
Michael Chan