Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verified, achieving remote code execution as root due to the Boa web server executing the CGI environment with root privileges.
History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Netis-systems
Netis-systems nc63
Vendors & Products Netis-systems
Netis-systems nc63

Mon, 24 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
Description Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verified, achieving remote code execution as root due to the Boa web server executing the CGI environment with root privileges.
Title Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-08-24T15:42:33.056Z

Updated: 2026-08-24T15:42:33.056Z

Reserved: 2026-08-18T21:04:48.503Z

Link: CVE-2026-76071

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-24T16:17:23.117

Modified: 2026-08-24T16:17:23.117

Link: CVE-2026-76071

cve-icon Redhat

No data.