CVE-2019-8985 Details
Description
On Netis WF2411 with firmware 2.1.36123 and other Netis WF2xxx devices (possibly WF2411 through WF2880), there is a stack-based buffer overflow that does not require authentication. This can cause denial of service (device restart) or remote code execution. This vulnerability can be triggered by a GET request with a long HTTP "Authorization: Basic" header that is mishandled by user_auth->user_ok in /bin/boa.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/WhooAmii/whooamii.github.io/blob/master/2018/netis/buffer%20overflow.md | CVE | ExploitVendor Advisory |
| https://github.com/WhooAmii/whooamii.github.io/blob/master/2018/netis/buffer%20overflow.md | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| netis-systems wf2411 firmware | 2.1.36123 |
CPE
Remediation
| |
| netis-systems wf2411 | All versions |
CPE
Remediation
| |
| netis-systems wf2880 firmware | 2.1.36123 |
CPE
Remediation
| |
| netis-systems wf2880 | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Aug 24, 2020 | CWE Remap | [email protected] |
| Mar 28, 2019 | CVE Modified | [email protected] |
| Feb 22, 2019 | Initial Analysis | [email protected] |