Vulnerability record · CVE-2021-26747 · published 18 February 2021
CVE-2021-26747: Netis router ping command shell metacharacter injection RCE
Netis Systems · Wf2780 Firmware
Netis WF2780 and WF2411 firmware pass unsanitized input into the ping command, allowing shell metacharacter injection. Because the flaw is reachable over the network with no authentication, it exposes affected routers to remote code execution.
Description
Netis WF2780 2.3.40404 and WF2411 1.1.29629 devices allow Shell Metacharacter Injection into the ping command, leading to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable command injection with a 9.8 CVSS score and high EPSS probability makes this an urgent patching priority.
What it is
Netis WF2780 and WF2411 firmware pass unsanitized input into the ping command, allowing shell metacharacter injection. Because the flaw is reachable over the network with no authentication, it exposes affected routers to remote code execution.
Impact
An unauthenticated remote attacker can execute arbitrary shell commands on the device, gaining full control of the router and its network position.
Attack surface
The CVSS vector is AV:N/AC:L/PR:N/UI:N, so the ping functionality is reachable over the network with no authentication and no user interaction.
Exploitation
CVE-2021-26747 is not listed in CISA KEV, but EPSS is 0.54777 (98.9th percentile) and public exploit code is referenced on GitHub, indicating meaningful exploitation activity.
What to do
- Apply the latest Netis firmware for WF2780 and WF2411; if no fixed release exists, replace or retire the devices.
- Disable remote administration and restrict the router management interface to trusted LAN segments only.
- Block external access to the router web/ping interface at the network perimeter.
- Segment or isolate affected routers so a compromise cannot pivot into other network assets.
- Monitor vendor advisories for updated firmware since the record does not specify fixed versions.
Detection
- Inspect router and perimeter logs for ping requests containing shell metacharacters such as ;, |, &, $, or backticks.
- Alert on unexpected outbound connections or processes originating from router management IPs.
- Review router configuration changes and new accounts for signs of post-exploitation.
- Use network monitoring to detect anomalous traffic from affected Netis devices to external hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.netis-systems.com.tw/ | ProductVendor Advisory |
| https://github.com/yhstar00/netis-route | ExploitThird Party Advisory |
| http://www.netis-systems.com.tw/ | ProductVendor Advisory |
| https://github.com/yhstar00/netis-route | ExploitThird Party Advisory |
Track CVE-2021-26747 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-26747), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.