CVE-2025-50616

7.5

Netis · WF2880

A buffer overflow vulnerability exists in the Netis WF2880 v2.1.40207 router, specifically within the cgitest.cgi file, which allows unauthenticated attackers to cause a Denial of Service.

Executive summary

A critical buffer overflow vulnerability in Netis WF2880 routers allows unauthenticated remote attackers to trigger a Denial of Service condition.

Vulnerability

The vulnerability exists in the FUN_0046f984 function of the cgitest.cgi file. An unauthenticated attacker can trigger this flaw by sending a crafted payload containing a manipulated wl_advanced_set value, resulting in a system crash.

Business impact

The exploitation of this vulnerability results in a Denial of Service, which can render the affected networking hardware unavailable for legitimate traffic. Given a CVSS score of 7.5, this represents a high risk to business continuity, as it allows remote attackers to disrupt critical network infrastructure without requiring prior authentication or user interaction.

Remediation

Immediate Action: Since no vendor patch is currently confirmed, administrators should restrict access to the web management interface of the Netis WF2880 to trusted internal networks only.

Proactive Monitoring: Monitor system logs for frequent reboots or service interruptions related to the cgitest.cgi endpoint.

Compensating Controls: Implement an edge firewall rule to block external traffic destined for the web management port of the affected device.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the research write-up provided by the vulnerability reporter.

Analyst recommendation

Given the availability of a public proof-of-concept and the potential for service disruption, organizations utilizing the Netis WF2880 must treat this vulnerability with high priority. We recommend immediate isolation of the device management interface from public-facing networks until a firmware update is released by the vendor.

More Netis CVEs

Sources