Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter
Published Aug 24, 2026
9.3
CRITICALCVSS 4.0
EPSS 1.42%
Description
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verified, achieving remote code execution as root due to the Boa web server executing the CGI environment with root privileges.
Affected products
-
Affected
- ≥ 0, ≤ 3.0.0.3327
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Netis Systems | NC63 | affected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-64922 Advisory
- https://github.com/ozcanpng/CVE-2026-76071 technical-descriptionexploit
- https://ozcanpng.dev/blog/cve-2026-76071-netis-nc63-ipfilter-stack-buffer-overflow/ technical-descriptionexploit
- https://www.netis-systems.com/products/NC63.html product
- https://www.vulncheck.com/advisories/netis-nc63-stack-buffer-overflow-via-desthost-parameter third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-64922 | Advisory | |
| https://github.com/ozcanpng/CVE-2026-76071 | technical-descriptionexploit | |
| https://ozcanpng.dev/blog/cve-2026-76071-netis-nc63-ipfilter-stack-buffer-overflow/ | technical-descriptionexploit | |
| https://www.netis-systems.com/products/NC63.html | product | |
| https://www.vulncheck.com/advisories/netis-nc63-stack-buffer-overflow-via-desthost-parameter | third-party-advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data