CVE-2026-36540: n/a
Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_pwd_confirm POST parameters are passed directly to the underlying OS shell without sanitization. An attacker can inject arbitrary shell commands by wrapping them in backticks (`) and encoding them in base64. Because the endpoint requires no authentication, any device on the LAN can achieve full Remote Code Execution on the router's operating system with a single HTTP POST request.
AI Analysis
Technical Summary
The Netis AC1200 Router NC21 firmware version 4.0.1.4296 is vulnerable to unauthenticated command injection through the /cgi-bin/skk_set.cgi endpoint. Specifically, the password and new_pwd_confirm POST parameters are directly passed to the underlying operating system shell without proper input sanitization. Attackers can inject arbitrary shell commands by encoding them in base64 and wrapping them in backticks (`). Since the endpoint does not require authentication, any device on the local network can exploit this vulnerability to achieve full remote code execution on the router's OS with a single HTTP POST request. This vulnerability is tracked as CVE-2026-36540 and is associated with CWE-77 (Improper Neutralization of Special Elements used in a Command).
Potential Impact
Successful exploitation allows an unauthenticated attacker on the local network to execute arbitrary commands on the router's operating system, leading to full remote code execution. This compromises the confidentiality, integrity, and availability of the device, potentially allowing control over network traffic and device configuration.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict LAN access to trusted devices only and consider isolating the router management interface from untrusted local devices. Monitor vendor communications for official patches or updates addressing this vulnerability.
CVE-2026-36540: n/a
Description
Netis AC1200 Router NC21 V4.0.1.4296 is vulnerable to unauthenticated command injection via the /cgi-bin/skk_set.cgi endpoint. The password and new_pwd_confirm POST parameters are passed directly to the underlying OS shell without sanitization. An attacker can inject arbitrary shell commands by wrapping them in backticks (`) and encoding them in base64. Because the endpoint requires no authentication, any device on the LAN can achieve full Remote Code Execution on the router's operating system with a single HTTP POST request.
CVSS v3.1
Score 7.3high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Netis AC1200 Router NC21 firmware version 4.0.1.4296 is vulnerable to unauthenticated command injection through the /cgi-bin/skk_set.cgi endpoint. Specifically, the password and new_pwd_confirm POST parameters are directly passed to the underlying operating system shell without proper input sanitization. Attackers can inject arbitrary shell commands by encoding them in base64 and wrapping them in backticks (`). Since the endpoint does not require authentication, any device on the local network can exploit this vulnerability to achieve full remote code execution on the router's OS with a single HTTP POST request. This vulnerability is tracked as CVE-2026-36540 and is associated with CWE-77 (Improper Neutralization of Special Elements used in a Command).
Potential Impact
Successful exploitation allows an unauthenticated attacker on the local network to execute arbitrary commands on the router's operating system, leading to full remote code execution. This compromises the confidentiality, integrity, and availability of the device, potentially allowing control over network traffic and device configuration.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict LAN access to trusted devices only and consider isolating the router management interface from untrusted local devices. Monitor vendor communications for official patches or updates addressing this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-04-06T00:00:00.000Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a16f9d0e29bf47b50c0e784
Added to database: 05/27/2026, 14:04:00 UTC
Last enriched: 07/05/2026, 21:46:48 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 52
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.