← Terug naar overzicht

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability in netis.cgi. Unauthenticated remote attackers can exploit the vulnerability by supplying an oversized destHost parameter to the ipFilterList=mod action. The root cause is widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers without prior authentication checks. Successful exploitation allows overwriting saved stack state and achieving remote code execution. The impact is critical as code executes with root privileges due to the Boa web server running the CGI environment as root. No authentication is required to trigger the vulnerability, making it trivially exploitable remotely. The vulnerability affects all firmware versions up to and including V3.0.0.3327. A proof-of-concept and detailed write-up have been published publicly, increasing exploitation risk.

Affected products

  • Netis NC63 firmware V3.0.0.3327 and below

Related CVE's

  • CVE-2026-76071

Categories

  • Mobile & IoT
  • Network Infrastructure
  • Zero-Day Vulnerabilities