CVE-2026-76071
Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verified, achieving remote code execution as root due to the Boa web server executing the CGI environment with root privileges.
| CWE | CWE-121 |
| Vendor | netis systems |
| Product | nc63 |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for netis systems nc63
Be the first to know when new critical vulnerabilities affecting netis systems nc63 are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
Netis Systems / NC63
0 β€ 3.0.0.3327
References
ozcanpng.dev: https://ozcanpng.dev/blog/cve-2026-76071-netis-nc63-ipfilter-stack-buffer-overflow/ github.com: https://github.com/ozcanpng/CVE-2026-76071 netis-systems.com: https://www.netis-systems.com/products/NC63.html vulncheck.com: https://www.vulncheck.com/advisories/netis-nc63-stack-buffer-overflow-via-desthost-parameter
Credits
Γzcan Ersan (@ozcanpng)