Junglewise Threat Intelligence

CVE-2026-76071: Netis NC63 stack buffer overflow in IP filter handler

CVE-2026-76071 · Severity: critical · CVSS 9.8 · Published 2026-08-24

Executive brief

The Netis NC63 is a wireless router used to provide network connectivity in homes and small businesses. A vulnerability in its web configuration interface allows attackers to send specially crafted network requests without logging in, causing the router to crash or execute malicious code with full system privileges. This could allow attackers to gain complete control of the router, intercept network traffic, or launch attacks on connected devices.

Technical details

CVE-2026-76071 is a pre-authentication stack-based buffer overflow in the /cgi-bin/skk_set.cgi endpoint of Netis NC63 firmware. The vulnerability exists in a generic MIB/value parser (type-0x0c handler) that processes the destHost parameter using sscanf with a widthless scanset format specifier (%[^,]) that copies user-supplied input into fixed-size 16-byte stack buffers without bounds checking. An unauthenticated remote attacker can send a POST request to /cgi-bin/skk_set.cgi with ipFilterList=mod and an oversized destHost parameter containing no commas, causing the sscanf conversion to overflow the stack and overwrite the saved return address. Since the Boa web server executes CGI handlers as root, successful exploitation achieves remote code execution as root. The vulnerability has been demonstrated with dynamic testing confirming PC control and successful system() call invocation.

Affected products

  • Netis NC63 through V3.0.0.3327

Timeline

  • 2026-08-24: disclosed
  • other: CVE assigned by VulnCheck

References