Netis AC1200 Router Hard-Coded Root Credential Vulnerability

Vulnerability

A hard-coded root password vulnerability has been identified in the Netis AC1200 Router NC21, specifically in the firmware version V4.0.1.4296. The root password is set to 'root' and is stored in '/etc/shadow.sample'. This vulnerability allows local attackers with access to the device to authenticate as root and gain full control over the operating system.

Impact

Exploitation of this vulnerability allows for unauthorized root access, enabling full control of the device's operating system.

Reproduction

To reproduce this vulnerability, access the router via SSH using the root username and the default password 'root'. The SSH connection must be established with specific options to negotiate the key exchange algorithm, host key algorithm, accepted public key algorithm, cipher, and compression settings.

Added: May 28, 2026, 2:45 AM
Updated: May 28, 2026, 2:45 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.0
remediation
0.0
relevance
9.1
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.