CVE-2025-50616
7.5Netis · WF2880
A buffer overflow vulnerability exists in the Netis WF2880 v2.1.40207 router, specifically within the cgitest.cgi file, which allows unauthenticated attackers to cause a Denial of Service.
Executive summary
A critical buffer overflow vulnerability in Netis WF2880 routers allows unauthenticated remote attackers to trigger a Denial of Service condition.
Vulnerability
The vulnerability exists in the FUN_0046f984 function of the cgitest.cgi file. An unauthenticated attacker can trigger this flaw by sending a crafted payload containing a manipulated wl_advanced_set value, resulting in a system crash.
Business impact
The exploitation of this vulnerability results in a Denial of Service, which can render the affected networking hardware unavailable for legitimate traffic. Given a CVSS score of 7.5, this represents a high risk to business continuity, as it allows remote attackers to disrupt critical network infrastructure without requiring prior authentication or user interaction.
Remediation
Immediate Action: Since no vendor patch is currently confirmed, administrators should restrict access to the web management interface of the Netis WF2880 to trusted internal networks only.
Proactive Monitoring: Monitor system logs for frequent reboots or service interruptions related to the cgitest.cgi endpoint.
Compensating Controls: Implement an edge firewall rule to block external traffic destined for the web management port of the affected device.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the research write-up provided by the vulnerability reporter.
Analyst recommendation
Given the availability of a public proof-of-concept and the potential for service disruption, organizations utilizing the Netis WF2880 must treat this vulnerability with high priority. We recommend immediate isolation of the device management interface from public-facing networks until a firmware update is released by the vendor.