GHSA-x2w7-3ffq-rg3v · Severity: high — Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the ...
Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_pwd_confirm POST parameters are passed directly to the underlying OS shell without sanitization. An attacker can inject arbitrary shell commands by wrapping them in backticks (`) and encoding them in base64. Because the endpoint requires no authentication, any device on the LAN can achieve full Remote Code Execution on the router's operating system with a single HTTP POST request.
Conclusion & alert: CVE-2026-36540 is rated Moderate Risk (57.6/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.27%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-02 | 0.83% | 1.27% | +0.43% |
| 2 | 2026-05-29 | 0.21% | 0.83% | +0.62% |
| 3 | 2026-05-28 | — | 0.21% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.3 | 3.1 | HIGH |
|
3.9 | 3.4 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-x2w7-3ffq-rg3v · Severity: high — Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the ...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||