← Vulnerability feed

Vulnerability record · CVE-2019-19356 · published 7 February 2020

CVE-2019-19356: Netis WF2419 router command injection in tracert tool allows root RCE

Netis Systems · Wf2419 Firmware

Netis WF2419 firmware versions V1.2.31805 and V2.2.36123 fail to sanitize user input in the tracert diagnostic tool on the web management page, allowing OS command injection (CWE-78). An authenticated user can execute arbitrary system commands as root, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog.

7.5 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 28% · top 1.9% CWE-78 · OS command injection
7.5CVSS 3.1 base score, v2 8.5
28%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
7References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw yields root code execution, has public exploit references, and is in CISA's KEV catalog, though it requires authenticated access to the management interface.

What it is

Netis WF2419 firmware versions V1.2.31805 and V2.2.36123 fail to sanitize user input in the tracert diagnostic tool on the web management page, allowing OS command injection (CWE-78). An authenticated user can execute arbitrary system commands as root, and the flaw is listed in CISA's Known Exploited Vulnerabilities catalog.

Impact

An attacker with access to the management interface gains root-level command execution on the router, enabling full device compromise, traffic interception or redirection, and use of the device as a foothold into the network.

Attack surface

Reachable over the network via the router's web management page (CVSS vector AV:N); the attacker must be authenticated to that page (PR:L) and no user interaction is required (UI:N).

Exploitation

CISA added this to the KEV catalog on 2021-11-03 with a 2022-05-03 remediation due date, and multiple public references are tagged Exploit; EPSS 30-day probability is 0.28168 (98th percentile). No ransomware campaign use is documented.

What to do

  • Apply the vendor's firmware update for WF2419; if no fixed firmware exists for the deployed version, replace the device or take it off untrusted networks.
  • Restrict access to the router web management interface to a trusted management VLAN or specific administrative hosts.
  • Change default administrative credentials and enforce strong, unique passwords to reduce the authenticated access this flaw requires.
  • Disable remote/WAN-side management access to the web interface where the feature is not needed.
  • Monitor vendor advisories for end-of-support status and plan replacement of unsupported units.

Detection

  • Review router logs for unexpected or malformed requests to the tracert/diagnostic endpoints of the web management page.
  • Alert on outbound connections or DNS lookups originating from the router itself that are not part of normal operations.
  • Audit management-page authentication logs for logins from unusual source addresses or at unusual times.
  • Check for unexpected configuration changes, new admin accounts, or altered DNS settings on WF2419 devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2019-19356 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Netis WF2419 Devices Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-19356 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-6391Netis-systems wf2419 firmware cross-site request forgery vulnerabilityA cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete Address Re…EPSS 0.96%5.4CVE-2018-5967Netis-systems wf2419 firmware cross-site scripting vulnerabilityNetis WF2419 V2.2.36123 devices allow XSS via the Description parameter on the Bandwidth Control Rule Settings page.EPSS 0.67%5.4CVE-2018-6190Netis-systems wf2419 firmware cross-site scripting vulnerabilityNetis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.EPSS 1.6%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed

Source: NIST National Vulnerability Database (record CVE-2019-19356), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.