CVE-2019-19356 is an authenticated command injection vulnerability in the Netis WF2419 wireless router web management interface that leads to remote code execution as root. The issue affects firmware versions V1.2.31805 and V2.2.36123. The vulnerable functionality is the tracert diagnostic tool exposed through the administrative web UI. Because user-supplied input is not properly sanitized before being passed to the underlying system command, an authenticated attacker can inject arbitrary shell commands and have them executed with root privileges on the device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python proof-of-concept exploit for CVE-2019-19356, targeting the Netis WF2419 router (firmware versions V1.2.31805 and V2.2.36123). The exploit leverages an authenticated command injection vulnerability in the router's web management interface, specifically in the 'tracert' diagnostic tool accessible via the '/cgi-bin-igd/netcore_set.cgi' endpoint. By sending a specially crafted POST request with a command injection payload, the attacker can execute arbitrary shell commands as root on the device. The output of the command is then retrieved from the '/cgi-bin-igd/netcore_get.cgi' endpoint. The exploit requires network access to the router's web interface and valid credentials (default credentials may suffice). The repository consists of the main exploit script ('CVE-2019-19356_exploit.py') and a README file detailing the vulnerability, prerequisites, and usage instructions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown
A remote code execution vulnerability in Netis WF2419 tracert functionality that can be exploited with default credentials and verified via out-of-band callbacks.
A high-severity remote code execution vulnerability in Netis WF2419 wireless routers affecting a diagnostic tool utility, allowing authenticated command execution via multiple parameters such as IP address or domain name.
A vulnerability listed as one of the infection exploits used by Mirai variant four to infect additional vulnerable hosts.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.