CVE-2025-50608

7.5

Netis · WF2880 v2

A buffer overflow in the cgitest.cgi file of Netis WF2880 v2.1.40207 allows unauthenticated attackers to cause a denial of service via a crafted wl_base_set parameter.

Executive summary

A buffer overflow vulnerability in the Netis WF2880 v2 router allows unauthenticated remote attackers to trigger a denial of service condition.

Vulnerability

This is a buffer overflow vulnerability located in the FUN_00471994 function of the cgitest.cgi file. An unauthenticated attacker can trigger the crash by injecting a crafted value into the wl_base_set parameter.

Business impact

The vulnerability carries a CVSS score of 7.5, reflecting a significant risk to service availability. Successful exploitation results in a denial of service, which can disrupt network connectivity for all users reliant on the affected hardware. This creates a high risk of operational downtime and potential loss of business continuity.

Remediation

Immediate Action: Monitor the vendor support portal for official firmware updates that address this buffer overflow. If no patch is available, isolate the affected device from the public internet to prevent remote exploitation.

Proactive Monitoring: Review system logs for frequent, unexplained reboots or crashes of the cgitest.cgi service. Monitor network traffic for malformed HTTP requests targeting the cgitest.cgi endpoint.

Compensating Controls: Implement a Web Application Firewall (WAF) rule to inspect and drop incoming traffic containing suspicious or oversized payloads in the wl_base_set parameter. Restrict administrative access to the device to trusted management IP addresses only.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the research repository referenced by the CVE record.

Analyst recommendation

Given the availability of a public proof-of-concept and the ease with which this vulnerability can be triggered, the risk to the availability of the Netis WF2880 v2 is elevated. Administrators should prioritize restricting network access to the device immediately. Once the vendor releases a firmware patch, it must be applied across all affected units to fully remediate the underlying buffer overflow risk.

More Netis CVEs

Sources