Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-76070: Netis NC63 firmware lets attacker run code via login

CVE-2026-76070 · published 10 days ago
Summary

The web interface on Netis NC63 routers (up to firmware version V3.0.0.3327) can be fooled by sending an overly long, specially encoded password. This overload lets an unauthenticated remote user take full control of the device with administrator rights. Update the router to the latest firmware from Netis, disable remote management if not needed, and use strong, unique passwords.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
netis systems nc63 <= 3.0.0.3327
Original advisory text
Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi. Attackers can exploit the custom Base64 decoder's lack of output length validation against the fixed-size stack buffer to achieve remote code execution with root privileges, as the Boa web server executes the CGI environment as root.
Severity
9.3 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 1%
Type
CWE-121Stack-based Buffer Overflow
Timeline
Published24 Aug 2026
Updated30 Aug 2026
First seen24 Aug 2026
Sources
CVE-2026-76070 · MITRE
Monitor software like this
Free during beta