S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 14, 2025

CVE-2024-48455 Scanner

CVE-2024-48455 Scanner - Information Disclosure vulnerability in Netis Wifi Router

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-48455
2.7
CVSSlow
Exploitable remotely over the internet · requires high privileges.

An issue in Netis Wifi6 Router NX10 2.0.1.3643 and 2.0.1.3582 and Netis Wifi 11AC Router NC65 3.0.0.3749 and Netis Wifi 11AC Router NC63 3.0.0.3327 and 3.0.0.3503 and Netis Wifi 11AC Router NC21 3.0.0.3800, 3.0.0.3500 and 3.0.0.3329 and Netis Wifi Router MW5360 1.0.1.3442 and 1.0.1.3031 allows a remote attacker to obtain sensitive information via the mode_name, wl_link parameters of the skk_get.cgi component.

Attack Vector
Network
Privileges Req.
High
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Netis Wifi Routers are popular networking devices used in homes and small businesses to provide wireless internet access. These routers are valued for their affordability, ease of use, and compatibility with various networking environments. They are commonly employed to manage local network traffic and internet connectivity.

The vulnerability identified in multiple Netis Wifi Router models involves Information Disclosure. This flaw enables remote attackers to access sensitive information such as configuration details, vendor data, and network statistics via the skk_get.cgi component.

The issue lies in the improper handling of HTTP POST requests to the skk_get.cgi endpoint. By sending crafted requests with parameters like mode_name and wl_link, attackers can retrieve sensitive data from the router's response. The affected parameters are not adequately protected, leading to unauthorized data exposure.

Exploitation of this vulnerability can result in exposure of sensitive router configuration details, which may include version numbers, network statistics, and vendor-specific data. This information can aid attackers in further compromising the network or exploiting other vulnerabilities.

REFERENCES

Solution Advice
  • Update the firmware of the affected Netis Wifi Routers to the latest version that addresses this vulnerability.
  • Restrict access to administrative interfaces and endpoints to authorized IP addresses only.
  • Disable unnecessary features and endpoints such as skk_get.cgi if not required.
  • Implement strong authentication mechanisms for accessing router settings.
  • Regularly monitor and audit network logs for unusual activities targeting sensitive endpoints.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.