CVE-2025-50635

7.5

Netis · WF2780

A null pointer dereference in the Netis WF2780 cgitest.cgi file allows unauthenticated remote attackers to trigger a denial of service via a crafted CONTENT_LENGTH variable.

Executive summary

A critical null pointer dereference vulnerability in the Netis WF2780 router allows unauthenticated attackers to crash the device, resulting in a complete denial of service.

Vulnerability

The vulnerability exists within the FUN_0048a728 function of the cgitest.cgi file. An unauthenticated attacker can trigger a crash by manipulating the CONTENT_LENGTH HTTP header, which results in a null pointer dereference.

Business impact

Successful exploitation of this flaw leads to a denial of service, effectively taking the network device offline. Given the CVSS score of 7.5, this high-severity vulnerability poses a significant risk to operational continuity, as attackers can disrupt critical network infrastructure without requiring any authentication.

Remediation

Immediate Action: Monitor official Netis support channels for firmware updates that address this null pointer dereference and apply them as soon as they become available.

Proactive Monitoring: Review system and access logs for unusual inbound HTTP traffic targeting the cgitest.cgi endpoint or repeated device reboots.

Compensating Controls: Implement network-level access control lists to restrict management interface access to trusted administrative IP addresses only, effectively isolating the vulnerable endpoint from the public internet.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists, as documented in the research repository referenced by the CVE record.

Analyst recommendation

This vulnerability presents a clear and immediate risk to the availability of the Netis WF2780 device. Security teams must prioritize restricting access to the device management interface while awaiting a permanent firmware patch from the vendor to remediate the underlying code defect.

More Netis CVEs

Sources