PT-2026-80908 · Netis · Nc63
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Netis NC63 versions prior to V3.0.0.3327
Description
An issue exists where unauthenticated remote attackers can overwrite the saved stack state by providing an oversized
destHost parameter to the ipFilterList=mod action in the 'netis.cgi' endpoint. This occurs because of widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verified. Since the Boa web server executes the CGI environment with root privileges, this can lead to remote code execution as root.Recommendations
Update Netis NC63 to a version newer than V3.0.0.3327.
Avoid using the
destHost parameter in the 'netis.cgi' endpoint until the update is applied.Exploit
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nc63