November 3, 2021 · Applied Cybernetics Group
CVE-2019-19356 — Netis WF2419 Devices
Netis WF2419 Devices Remote Code Execution Vulnerability
- Added to KEV
2021-11-03- Federal due date
2022-05-03- Vendor
- Netis
- Product
- WF2419 Devices
- EPSS
- 99.7th percentile (score 0.910, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-19356
CISA short description
Netis WF2419 devices contains an unspecified vulnerability that allows an attacker to perform remote code execution as root through the router's web management page.
Required action
Apply updates per vendor instructions.