CVE-2019-19356 - CVE House
Back to Database
Status published Unknown CVE-2019-19356

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE)...

Vulnerability Description

Netis WF2419 is vulnerable to authenticated Remote Code Execution (RCE) as root through the router Web management page. The vulnerability has been found in firmware version V1.2.31805 and V2.2.36123. After one is connected to this page, it is possible to execute system commands as root through the tracert diagnostic tool because of lack of user input sanitizing.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-19356

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

netis-systems

View all reports →

Affected Software

wf2419 firmware
Vulnerable Versions:
1.2.31805, 2.2.36123

Timeline

Official Publish: February 7th, 2020
Last Modified: October 21st, 2025
Added to House: July 20th, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.