HIGH CISA KEV

CVE-2019-19356

CVSS v3

7.5

HIGH

EPSS Score

91.1%

exploit probability

CISA KEV

Yes

known exploited

Exploitation

SSVC status

Description

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

CISA Known Exploited Vulnerability

Date Added
11/3/2021
Patch Due Date
5/3/2022
Ransomware Use
Unknown

Technical details

Published
2/7/2020

Frequently asked questions

What is CVE-2019-19356?

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

Is CVE-2019-19356 actively exploited?

Yes. CVE-2019-19356 is on the CISA Known Exploited Vulnerabilities (KEV) catalog, meaning it has been confirmed as actively exploited in the wild. CISA requires federal agencies to patch by 5/3/2022.

What is the CVSS score for CVE-2019-19356?

CVE-2019-19356 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2019-19356 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.