CVE-2026-73673: Netis NC63 V3.0.0.3327 Unauthenticated Firmware Update with Missing Cryptographic Firmware Authentication
Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/uploadfw.cgi without a valid session cookie, bypassing authentication because Boa grants access to any path containing '.cgi' regardless of cookie validation, and netis.cgi reads but does not enforce the authentication state before invoking the firmware update handler, which accepts images validated only by a forgeable additive checksum and static product strings rather than a cryptographic signature, potentially enabling persistent router compromise.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-73673?
CVE-2026-73673 has a severity rating of high with a score of 8.8.
How do I fix CVE-2026-73673?
To mitigate CVE-2026-73673, update your Netis NC63 router firmware to the latest version that addresses the unauthenticated firmware update vulnerability.
What types of attacks can exploit CVE-2026-73673?
CVE-2026-73673 can be exploited by unauthenticated attackers to upload and execute unsigned firmware images on affected routers.
Which devices are affected by CVE-2026-73673?
CVE-2026-73673 specifically affects Netis NC63 routers running firmware version V3.0.0.3327.
Is CVE-2026-73673 a remote or local vulnerability?
CVE-2026-73673 is a remote vulnerability, allowing attackers to exploit it over the network without authentication.