CVE-2026-73673
8.8Netis · Netis NC63 Wireless AC1200 Router
The Netis NC63 Wireless AC1200 Router firmware contains a vulnerability that allows for unauthenticated firmware updates due to missing authentication for critical functions.
Executive summary
The Netis NC63 Wireless AC1200 Router is vulnerable to unauthorized firmware updates, which could allow an attacker to gain persistent, high-level control over the device.
Vulnerability
The device suffers from a missing authentication for critical function vulnerability (CWE-306). An attacker on the local network can initiate unauthorized firmware updates, bypassing security checks and potentially installing malicious firmware.
Business impact
An attacker who successfully exploits this vulnerability can take full control of the router, potentially intercepting network traffic or using the device as a persistent foothold within the internal network. With a CVSS score of 8.8, this represents a severe security risk to all devices connected to the router.
Remediation
Immediate Action: Check the official Netis support website for firmware updates and apply the latest version as soon as it becomes available.
Proactive Monitoring: Monitor network traffic for unusual update requests to the router and restrict administrative access to the device to trusted, wired management segments only.
Compensating Controls: Disable remote management features on the router and ensure the device is not exposed to the public internet.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept repository is available on GitHub.
Analyst recommendation
Given the availability of a public proof-of-concept and the critical nature of firmware-level vulnerabilities, users must treat this issue with high priority. Apply vendor-provided security updates immediately and isolate the router management interface from untrusted networks.