← Back to browse · API

CVE-2019-19356

Severity
HIGH
CVSS
7.5
EPSS
0.28168
Risk score
64.86
CISA KEV
Yes
PoC
No
Published
2020-02-07
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2019-8977, GHSA-CH88-RXPC-5C5R
Products
Netis:WF2419 Devices, n/a:n/a n/a
Sources
cisa.gov CVE-2019-19356
euvd EUVD-2019-8977

Description

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

References