Netis NC63 firmware through V3.0.0.3327 contains a critical stack-based buffer overflow vulnerability in the login handler (/bin/netis.cgi). Unauthenticated remote attackers can submit an oversized Base64-encoded password to exploit the custom Base64 decoder's lack of output length validation. This allows overwriting of saved stack state and leads to remote code execution with root privileges. The vulnerability is particularly severe because the Boa web server runs the CGI environment as root. No authentication is required to exploit this flaw, making it accessible to any remote attacker. A proof-of-concept exploit and detailed write-up have been published publicly on GitHub and a personal blog. The issue has also been documented by VulnCheck. Affected users should update firmware or restrict access to the device's web management interface as a mitigation measure.