PT-2026-80907 · Netis · Nc63
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Netis NC63 versions prior to V3.0.0.3327
Description
A stack-based buffer overflow exists in the login handler of the '/bin/netis.cgi' endpoint. The issue occurs because the custom Base64 decoder fails to validate the output length against a fixed-size stack buffer when processing an oversized Base64-encoded password provided via the
password parameter. Since the Boa web server executes the CGI environment with root privileges, an unauthenticated remote attacker can overwrite the saved stack state to achieve remote code execution as root.Recommendations
Update Netis NC63 to a version newer than V3.0.0.3327.
As a temporary mitigation, restrict access to the '/bin/netis.cgi' endpoint to trusted networks only.
Exploit
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nc63