Netis E1+ version 1.2.32533 contains a hardcoded root account vulnerability that allows unauthenticated attackers to access the device with predefined credentials. Attackers can leverage the embedded root account with a crackable password to gain full administrative access to the network device.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 04 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Netis-systems
Netis-systems netis E1+
Vendors & Products Netis-systems
Netis-systems netis E1+

Tue, 03 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
Description Netis E1+ version 1.2.32533 contains a hardcoded root account vulnerability that allows unauthenticated attackers to access the device with predefined credentials. Attackers can leverage the embedded root account with a crackable password to gain full administrative access to the network device.
Title Netis E1+ 1.2.32533 - Backdoor Account (root)
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-03T22:01:51.893Z

Reserved: 2026-02-01T13:16:06.487Z

Link: CVE-2020-37092

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-03T22:16:25.340

Modified: 2026-02-03T22:16:25.340

Link: CVE-2020-37092

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-04T12:05:04Z

Weaknesses