CRITICAL
Netis Systems
CVE published 2026-09-08
CVE-2026-61516
CVE-2026-61516 is a critical information disclosure vulnerability in Netis NX10 firmware versions V4.0.1.5808 and V3.0.0.4142. An unauthenticated attacker can retrieve the administrator password by sending a request to the sysinfo action in the web management interface. This vulnerability allows attackers to establish a fully authenticated administrator session on the device.