PT-2026-80908 · Netis · Nc63

·

CVE-2026-76071

·

Published

2026-08-24

·

Updated

2026-08-25

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netis NC63 versions prior to V3.0.0.3327
Description An issue exists where unauthenticated remote attackers can overwrite the saved stack state by providing an oversized destHost parameter to the ipFilterList=mod action in the 'netis.cgi' endpoint. This occurs because of widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verified. Since the Boa web server executes the CGI environment with root privileges, this can lead to remote code execution as root.
Recommendations Update Netis NC63 to a version newer than V3.0.0.3327. Avoid using the destHost parameter in the 'netis.cgi' endpoint until the update is applied.

Exploit

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-76071

Affected Products

Nc63