CVE-2026-76071

9.8

Netis Systems · NC63

Netis NC63 firmware contains a stack-based buffer overflow in the ipFilterList action, allowing unauthenticated remote attackers to achieve remote code execution as root.

Executive summary

A critical stack-based buffer overflow in Netis NC63 firmware allows unauthenticated attackers to execute arbitrary code with root privileges.

Vulnerability

The vulnerability exists in the ipFilterList action of the netis.cgi script, where widthless sscanf conversions copy user-supplied input into a fixed-size stack buffer. This allows an unauthenticated attacker to overwrite the stack state and execute arbitrary code as root.

Business impact

The ability to execute code as root on a network gateway device represents a total compromise of network security. Exploitation could lead to the theft of sensitive data, permanent device bricking, or the use of the device as a launchpad for further network attacks.

Remediation

Immediate Action: Update to the latest firmware version once provided by the vendor. In the interim, disable remote management features and restrict access to the web interface to trusted administrative subnets.

Proactive Monitoring: Review system logs for unexpected crashes of the Boa web server or suspicious requests containing overly long strings in the destHost parameter.

Compensating Controls: Implement network-level access control lists (ACLs) to block unauthorized access to the web management interface of the NC63 device.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists on GitHub.

Analyst recommendation

This vulnerability is highly dangerous due to its unauthenticated nature and the high level of privilege granted upon execution. Organizations must treat this as a high-priority task and apply patches as soon as they are released by Netis Systems.

More Netis Systems CVEs