CVE-2025-50617

7.5

Netis · WF2880

A buffer overflow vulnerability in the Netis WF2880 router allows unauthenticated attackers to trigger a denial of service via a crafted payload sent to the cgitest.cgi endpoint.

Executive summary

A critical buffer overflow vulnerability in the Netis WF2880 router allows unauthenticated attackers to cause a denial of service, necessitating immediate network perimeter hardening.

Vulnerability

This is a buffer overflow vulnerability located in the FUN_0046ed68 function of the cgitest.cgi file. An unauthenticated attacker can trigger this flaw by manipulating the wps_set parameter in a crafted HTTP request.

Business impact

The exploitation of this vulnerability results in a Denial of Service (DoS) condition, rendering the affected network device unresponsive. With a CVSS score of 7.5, the impact is significant for organizations relying on this hardware for connectivity, as it could lead to total loss of network availability for connected users and services.

Remediation

Immediate Action: Since a patch is currently unavailable, administrators should restrict access to the device management interface and the vulnerable cgitest.cgi endpoint to trusted IP addresses only.

Proactive Monitoring: Monitor network traffic for unusual HTTP requests targeting the cgitest.cgi file, specifically looking for abnormally long or malformed wps_set parameters in the payload.

Compensating Controls: Deploy a Web Application Firewall (WAF) or an Intrusion Prevention System (IPS) rule to filter and block requests containing malicious payloads directed at the vulnerable endpoint.

Exploitation status

Public Exploit Available: Yes, a public proof of concept is available via the researcher's GitHub repository referenced in the vulnerability disclosure.

Analyst recommendation

The presence of a public proof of concept significantly elevates the risk of exploitation for this device. Given the lack of a vendor-provided patch, it is imperative to isolate the vulnerable hardware from the public internet immediately to prevent unauthorized disruption of service.

More Netis CVEs

Sources