Netis AC1200 Router NC21 firmware version V4.0.1.4296 exposes the CGI endpoint /cgi-bin/skk_get.cgi without requiring authentication. A remote attacker with access to the local network can issue a single HTTP GET request to this endpoint and receive the router’s full configuration in JSON format. The exposed data reportedly includes administrator credentials, WiFi passwords, PPPoE credentials, DDNS credentials, and inventory information for connected devices. The core flaw is missing authentication on a sensitive administrative function that returns highly sensitive configuration material.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
The repository contains two standalone Python 3 command-line utilities and a standard Python .gitignore. Both tools accept a target host and query the Netis CGI endpoint /cgi-bin/skk_get.cgi over plaintext HTTP, then parse the returned configuration data and assess whether unauthenticated sensitive configuration disclosure occurred. They account for malformed Netis JSON containing trailing commas and recursively inspect nested dictionaries/lists for credential-related names such as password, username, token, secret, WEP key, WDS WEP key, and PPP credentials. main.py is a comparatively safer audit/checking implementation: it reports device metadata, response details, and whether sensitive fields are populated, but does not decode or print their contents. m.py is the more directly exploitative implementation: it attempts Base64 decoding of sensitive string values and prints recovered values, including readable credentials. No fixed target IP, external callback, persistence, command execution, or destructive behavior is present; the target host is supplied by the operator.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.