Vulnerability record · CVE-2019-19356 · published 7 February 2020
CVE-2019-19356: Netis WF2419 router command injection in tracert tool allows root RCE
Netis Systems · Wf2419 Firmware
Netis WF2419 firmware versions V1.2.31805 and V2.2.36123 fail to sanitize user input in the tracert diagnostic tool on the web management page, allowing OS command injection (CWE-78). An authenticated user can execute arbitrary system commands as root, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw yields root code execution, has public exploit references, and is in CISA's KEV catalog, though it requires authenticated access to the management interface.
What it is
Netis WF2419 firmware versions V1.2.31805 and V2.2.36123 fail to sanitize user input in the tracert diagnostic tool on the web management page, allowing OS command injection (CWE-78). An authenticated user can execute arbitrary system commands as root, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker with access to the management interface gains root-level command execution on the router, enabling full device compromise, traffic interception or redirection, and use of the device as a foothold into the network.
Attack surface
Reachable over the network via the router's web management page (CVSS vector AV:N); the attacker must be authenticated to that page (PR:L) and no user interaction is required (UI:N).
Exploitation
CISA added this to the KEV catalog on 2021-11-03 with a 2022-05-03 remediation due date, and multiple public references are tagged Exploit; EPSS 30-day probability is 0.28168 (98th percentile). No ransomware campaign use is documented.
What to do
- Apply the vendor's firmware update for WF2419; if no fixed firmware exists for the deployed version, replace the device or take it off untrusted networks.
- Restrict access to the router web management interface to a trusted management VLAN or specific administrative hosts.
- Change default administrative credentials and enforce strong, unique passwords to reduce the authenticated access this flaw requires.
- Disable remote/WAN-side management access to the web interface where the feature is not needed.
- Monitor vendor advisories for end-of-support status and plan replacement of unsupported units.
Detection
- Review router logs for unexpected or malformed requests to the tracert/diagnostic endpoints of the web management page.
- Alert on outbound connections or DNS lookups originating from the router itself that are not part of normal operations.
- Audit management-page authentication logs for logins from unusual source addresses or at unusual times.
- Check for unexpected configuration changes, new admin accounts, or altered DNS settings on WF2419 devices.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-19356 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Netis WF2419 Devices Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/156588/Netis-WF2419-2.2.36123-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/shadowgatt/CVE-2019-19356 | ExploitThird Party Advisory |
| https://www.digital.security/en/blog/netis-routers-remote-code-execution-cve-2019-19356 | ExploitThird Party Advisory |
| http://packetstormsecurity.com/files/156588/Netis-WF2419-2.2.36123-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/shadowgatt/CVE-2019-19356 | ExploitThird Party Advisory |
| https://www.digital.security/en/blog/netis-routers-remote-code-execution-cve-2019-19356 | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-19356 | US Government Resource |
Track CVE-2019-19356 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-19356), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.