CVE-2026-36540 Details
Description
Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_pwd_confirm POST parameters are passed directly to the underlying OS shell without sanitization. An attacker can inject arbitrary shell commands by wrapping them in backticks (`) and encoding them in base64. Because the endpoint requires no authentication, any device on the LAN can achieve full Remote Code Execution on the router's operating system with a single HTTP POST request.
A command injection vulnerability has been identified in the Netis AC1200 Router NC21, specifically in the firmware version V4.0.1.4296. The vulnerability exists in the '/cgi-bin/skk_set.cgi' endpoint, where the 'password' and 'new_pwd_confirm' POST parameters are sent directly to the operating system shell without proper sanitization. This flaw allows attackers to execute arbitrary shell commands by enclosing them in backticks and encoding them in base64. Since the endpoint does not require authentication, any device on the local area network can exploit this vulnerability to achieve full remote code execution on the router's operating system with a single HTTP POST request.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 27, 2026CISA-ADP
Assessed May 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/sir3ns/cve-disclosure/blob/main/CVE-2026-36540/readme.md | CISA-ADP | ExploitTechnical Description |
| https://github.com/sir3ns/cve-disclosure/blob/main/CVE-2026-36540/readme.md | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Netis AC1200 Router NC21 | V4.0.1.4296 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2026 | CVE Modified | CISA-ADP |
| May 27, 2026 | New CVE Received | [email protected] |
Volerion