CVE-2025-50612
7.5Netis · WF2880 v2
A buffer overflow in the Netis WF2880 v2 cgitest.cgi file allows unauthenticated attackers to trigger a Denial of Service attack via the wl_sec_set parameter.
Executive summary
A critical buffer overflow vulnerability in the Netis WF2880 v2 router allows unauthenticated attackers to crash the device, leading to a Denial of Service.
Vulnerability
This vulnerability is a buffer overflow occurring within the FUN_004743f8 function of the cgitest.cgi file. An unauthenticated attacker can trigger the flaw by sending a crafted payload to the wl_sec_set parameter.
Business impact
The ability for an unauthenticated attacker to cause a Denial of Service (DoS) poses a significant risk to network availability. Given the CVSS score of 7.5, this high severity flaw could result in complete service disruption for users connected to the affected router, causing operational downtime and necessitating manual intervention to restore connectivity.
Remediation
Immediate Action: Since no official patch is currently available, administrators should restrict access to the web management interface, ensuring it is not exposed to the public internet.
Proactive Monitoring: Monitor device logs for unusual traffic patterns or frequent service restarts that may indicate attempted exploitation of the cgitest.cgi endpoint.
Compensating Controls: Implement firewall rules to block access to the management interface from untrusted networks and utilize an intrusion detection system to monitor for malformed HTTP requests targeting the vulnerable parameter.
Exploitation status
Public Exploit Available: Yes, a public proof of concept exists, as documented in the research repository referenced by the CVE record.
Analyst recommendation
This vulnerability presents a clear risk of service disruption. Because a public proof of concept is available, the likelihood of exploitation is elevated. Organizations currently using the Netis WF2880 v2 should isolate the device management interface from external access immediately and prioritize replacing the hardware or applying vendor firmware updates as soon as they become available.