PT-2025-33012 · Netis · Netis Wf2780

CVE-2025-50635

·

Published

2025-08-13

·

Updated

2025-08-15

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Netis WF2780 version 2.2.35445
Description: A null pointer dereference issue exists in the FUN 0048a728 function within the cgitest.cgi file. Exploitation involves controlling the CONTENT LENGTH variable, which can lead to a denial-of-service (DoS) attack.
Recommendations: Update to a newer version that contains a fix for this issue. As a temporary workaround, restrict access to the cgitest.cgi file to minimize the risk of exploitation.

Exploit

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-50635

Affected Products

Netis Wf2780