CVE-2025-50610
7.5Netis · WF2880
A buffer overflow in the cgitest.cgi file of Netis WF2880 v2.1.40207 allows unauthenticated attackers to cause a Denial of Service via a crafted wl_base_set_5g parameter.
Executive summary
A buffer overflow vulnerability in the Netis WF2880 router poses a significant risk of service disruption through unauthenticated remote exploitation.
Vulnerability
This is a buffer overflow vulnerability located in the FUN_00476598 function of the cgitest.cgi file. An unauthenticated attacker can trigger the flaw by sending a crafted payload within the wl_base_set_5g parameter, resulting in a system crash.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity due to the ease of remote exploitation without authentication. Successful exploitation leads to a Denial of Service, which can cause significant operational downtime and loss of network availability for organizations relying on this hardware for connectivity.
Remediation
Immediate Action: Contact the vendor for firmware update availability and apply it immediately to the affected hardware to remediate the buffer overflow condition.
Proactive Monitoring: Monitor device logs for unusual traffic patterns targeting the cgitest.cgi endpoint or repeated device reboots that may indicate automated crash attempts.
Compensating Controls: Implement network segmentation to isolate the management interface from the public internet and use a firewall to restrict access to the web administration interface to trusted IP addresses only.
Exploitation status
Public Exploit Available: Yes, a proof-of-concept exists as documented in the researcher write-up referenced in the CVE record.
Analyst recommendation
Given the high CVSS score and the existence of a public proof-of-concept, this vulnerability should be prioritized for remediation. Organizations using Netis WF2880 routers should restrict management access immediately and apply vendor-supplied patches as soon as they become available to prevent potential service outages.