CVE-2026-61516
CRITICAL
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Sep 08, 2026
Vendor
unknown
Description
Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information disclosure vulnerability that allows unauthenticated attackers to retrieve the administrator password by sending a request to the sysinfo action in the web management interface without a valid session. Attackers can replay the exposed credential against the login handler to establish a fully authenticated administrator session on the device.