Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76070— Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter

Quick assessment

Affected
Netis Systems NC63
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Netis NC63 固件 V3.0.0.3327 版本存在一个基于栈的缓冲区溢出漏洞。未认证的远程攻击者可通过向 /bin/netis.cgi 中的登录处理函数提交过大的 Base64 编码密码,覆盖保存的栈状态。攻击者可利用自定义 Base64 解码器在对固定大小栈缓冲区进行输出长度验证方面的缺失,实现远程代码执行,并获得 root 权限,因为 Boa Web 服务器以 root 权限运行 CGI 环境。

CVSS 9.8 · Critical

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76070

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi. Attackers can exploit the custom Base64 decoder's lack of output length validation against the fixed-size stack buffer to achieve remote code execution with root privileges, as the Boa web server executes the CGI environment as root.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
栈缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Netis Systems NC63 0 ~ 3.0.0.3327 -

II. Public POCs for CVE-2026-76070

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 10548 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-76070

登录查看更多情报信息。

Vendor Advisories for CVE-2026-76070 (1)

Exploits & Public PoCs for CVE-2026-76070 (1)

Security Blog Posts for CVE-2026-76070 (1)

Vendor Pages for CVE-2026-76070 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-76070

No comments yet


Leave a comment