---
id: CVE-2026-61517
title: >-
  Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command
  injection vulnerability in the ping diagnostic handler that allows
  authenticated administrators to execute arbitrary shell commands as root by
  injecting into the IpAdd…
summary: >-
  Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command
  injection vulnerability in the ping diagnostic handler that allows
  authenticated administrators to execute arbitrary shell commands as root by
  injecting into the IpAdd…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: Netis Systems
product: NX10
affected:
  - NX10 4.0.1.5808
  - NX10 3.0.0.4142
published: '2026-09-08'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T14:17:03.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-61517'
references:
  - url: 'https://hackwithmike.com/research/advisories/netis/cve-2026-61517'
    label: disclosure@vulncheck.com
  - url: 'https://hackwithmike.com/research/netis/2026-09'
    label: disclosure@vulncheck.com
  - url: 'https://www.netis-systems.com/products/NX10.html'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/netis-nx10-os-command-injection-via-ping-diagnostic-handler
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-10T13:49:11.266253Z'
epss: 0.01573
epssPercentile: 0.7435
ingestedAt: '2026-09-08T15:33:26.985Z'
---

## Overview

Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command injection vulnerability in the ping diagnostic handler that allows authenticated administrators to execute arbitrary shell commands as root by injecting into the IpAddr parameter. The parameter is interpolated directly into a shell command executed through system() with an incomplete denylist that only blocks spaces, pipes, semicolons, and ampersands, leaving command substitution and alternate field separator expansion available for exploitation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
