EXPOSURES › CVE-2019-19356
CVE-2019-19356
HIGH ⌖ ON CISA KEV · EXPLOITEDNetis WF2419 routers allow remote code execution as root via their web management page.
An unspecified vulnerability in Netis WF2419 devices enables attackers to execute arbitrary code as root through the web management interface. This is a critical failure for DIB organizations because it provides a direct path for ransomware or data exfiltration without requiring user interaction, and the device is already listed in CISA's KEV catalog as actively exploited. Organizations must immediately patch or replace these devices and ensure no such hardware is in their unmanaged network segments.
Shame score — The device is actively exploited in the wild (KEV) and allows root-level remote code execution, indicating a severe, avoidable security failure in a consumer-grade IoT device that should not be in a DIB environment.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.
"Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page."