External risk intelligence

Netis NX10 Credential Disclosure Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-61516

The vulnerability exists in the web management interface of a network router. Such administrative interfaces are frequently exposed to the internet, either by design or through misconfiguration, and this specific endpoint is accessible without authentication.

Information Disclosure

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a vulnerability in Netis NX10 firmware that could allow an unauthenticated attacker to access administrator credentials and gain full control of the device. This information disclosure happens through the web management interface, potentially exposing sensitive administrative access. The main concern is confirming the relevance and exposure of this technology within our environment.

  • Unauthenticated access to admin credentials.
  • Allows unauthorized control of network devices.
  • Assess affected devices and exposure.

Attack Path

How an attacker could exploit the issue

An attacker can access an unauthenticated web interface on the router to request system information, which includes the administrator password. This exposed credential can then be used to log in to the router's administrative interface, giving the attacker full control.

  • No authentication required.
  • Request sysinfo action.
  • Full administrator access gained.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated attacker to obtain the administrator password for the device's web management interface. This information could then be used to gain full administrative control over the device.

  • Administrator credentials could be exposed.
  • An unauthenticated request to the web interface.
  • Full administrator control of the device.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in Netis NX10 firmware exposes administrator credentials through the web management interface. Network and security teams are likely responsible for identifying and securing these devices, as they often manage network edge infrastructure. The first practical step is to determine if any Netis NX10 devices are deployed, confirm their exposure and criticality, and then coordinate remediation with the vendor or implement compensating controls if immediate patching is not feasible.

  • Network and security teams own the issue.
  • Verify device deployment and internet exposure.
  • Plan vendor coordination or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Netis NX10?

The Netis NX10 is a network router designed to manage home or small office internet traffic. It acts as the gateway between a local network and the internet, providing connectivity to connected devices. The firmware versions V4.0.1.5808 and V3.0.0.4142 manage the internal processes of this hardware, including the web-based management interface used by administrators to configure network settings, security policies, and device performance.

What does CVE-2026-61516 mean?

This is an information disclosure vulnerability. It is classified under CWE-522, which involves the insufficient protection of sensitive credentials. In the context of CVE-2026-61516, the router's software contains a flaw where a specific diagnostic endpoint incorrectly reveals the administrator password to anyone who asks for it, even without a valid login session.

How can an attacker trigger this vulnerability?

An attacker can trigger this by sending a specifically crafted request to the 'sysinfo' action on the device's web management interface. No prior authentication, password, or login session is required to make this request. The bug is not triggered by normal administrative activities or user-initiated configurations; it is exclusively accessible through this unauthorized, automated request for system information.

Is my device at risk if it is not facing the internet?

According to Halo Surface Signal, this vulnerability is considered highly relevant because these administrative interfaces are often exposed to the internet. If your device is configured to be accessible from the public internet, it is at higher risk. Devices restricted to an internal-only network are less immediately reachable by external actors, though they remain vulnerable to any attacker who has already gained access to your local network.

What steps should I take if I use a Netis NX10?

First, inventory your network to locate any Netis NX10 devices. Once identified, verify whether their web management interfaces are reachable from the internet. If you find affected units, prioritize checking for firmware updates from the manufacturer. If a patch is unavailable, restrict access to the management interface by disabling remote administration or placing the device behind a firewall to mitigate unauthorized access.

References