Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-76071— Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter

Quick assessment

Affected
Netis Systems NC63
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Netis NC63 固件 V3.0.0.3327 及更早版本存在栈缓冲区溢出漏洞,该漏洞允许未经身份验证的远程攻击者通过向 netis.cgi 中的 ipFilterList=mod 动作提供超长的 destHost 参数,从而覆盖已保存的栈状态。攻击者可以利用宽度不限的 sscanf 转换,在验证身份之前将用户提供的输入复制到固定大小的栈缓冲区中,从而在具有 root 权限的 Boa Web 服务器执行 CGI 环境时,实现以 root 身份进行的远程代码执行。

CVSS 9.8 · Critical EPSS 1.06% · P62

Affected Version Matrix 1

VendorProduct Version RangeStatus
Netis Systems NC63 ≤ 3.0.0.3327 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-76071

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verified, achieving remote code execution as root due to the Boa web server executing the CGI environment with root privileges.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
栈缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Netis Systems NC63 0 ~ 3.0.0.3327 -

II. Public POCs for CVE-2026-76071

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 10350 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-76071

登录查看更多情报信息。

Vendor Advisories for CVE-2026-76071 (1)

Exploits & Public PoCs for CVE-2026-76071 (1)

Security Blog Posts for CVE-2026-76071 (1)

Vendor Pages for CVE-2026-76071 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-76071

No comments yet


Leave a comment