Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netis-systems
Netis-systems nc63 |
|
| Vendors & Products |
Netis-systems
Netis-systems nc63 |
Mon, 24 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verified, achieving remote code execution as root due to the Boa web server executing the CGI environment with root privileges. | |
| Title | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T15:42:33.056Z
Reserved: 2026-08-18T21:04:48.503Z
Link: CVE-2026-76071
No data.
Status : Received
Published: 2026-08-24T16:17:23.117
Modified: 2026-08-24T16:17:23.117
Link: CVE-2026-76071
No data.
OpenCVE Enrichment
Updated: 2026-08-24T21:10:31Z
-
CWE-121
Stack-based Buffer Overflow