CVE-2026-76070
Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi. Attackers can exploit the custom Base64 decoder's lack of output length validation against the fixed-size stack buffer to achieve remote code execution with root privileges, as the Boa web server executes the CGI environment as root.
| CWE | CWE-121 |
| Vendor | netis systems |
| Product | nc63 |
| Published | Aug 24, 2026 |
| Last Updated | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for netis systems nc63
Be the first to know when new critical vulnerabilities affecting netis systems nc63 are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Netis Systems / NC63
0 β€ 3.0.0.3327
References
ozcanpng.dev: https://ozcanpng.dev/blog/cve-2026-76070-netis-nc63-login-stack-buffer-overflow/ github.com: https://github.com/ozcanpng/CVE-2026-76070 netis-systems.com: https://www.netis-systems.com/products/NC63.html vulncheck.com: https://www.vulncheck.com/advisories/netis-nc63-stack-buffer-overflow-via-login-password-parameter
Credits
Γzcan Ersan (@ozcanpng)