CVE-2026-76071: Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter

Published Aug 24, 2026
·
Updated

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verified, achieving remote code execution as root due to the Boa web server executing the CGI environment with root privileges.

Affected Software

1 affected component
Netis NC63 firmware<=V3.0.0.3327

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Netis NC63 to a version that resolves this vulnerability.

    Fixed in V3.0.0.3327
  2. Compensating control

    Block unauthenticated access to the Netis NC63 CGI endpoint (netis.cgi) that processes the ipFilterList=mod action and the destHost parameter until the device is updated to a non-vulnerable firmware.

Event History

Aug 24, 2026
CVE Published
via MITRE·03:42 PM
Data Sourced
via MITRE·03:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which systems are in scope?

Netis NC63 firmware through version V3.0.0.3327 is affected. No fixed version is identified in the available data.

2

Does exploitation require credentials or user interaction?

No. An unauthenticated remote attacker can reach the vulnerable CGI action over the network, with no user interaction required.

3

What level of access could an attacker obtain?

Successful exploitation can result in remote code execution as root, because the Boa web server runs the CGI environment with root privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203