CVE-2019-19356
Netis WF2419 Devices Remote Code Execution Vulnerability
- Published
- Feb 7, 2020
- Updated
- Oct 21, 2025
- Assigning CNA
- mitre
- Evidence observed
- Nov 3, 2021
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HModerate · next 30 days
- Percentile
- 98.1%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.
Sources
2- CVE-2019-19356Exploit
Netis router RCE exploit ( CVE-2019-19356)
Docker-based proof-of-concept exploit for CVE-2019-19356, enabling rapid reproduction and testing of the vulnerability in a controlled environment.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.