{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nc63-v3.0.0.3327/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-73673"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NC63 (V3.0.0.3327)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Netis"],"content_html":"\u003cp\u003eNetis NC63 router firmware version V3.0.0.3327 contains a critical vulnerability (CVE-2026-73673) that allows unauthenticated remote attackers to upload malicious firmware images to the device. The vulnerability stems from improper authentication enforcement within the Boa web server and the netis.cgi CGI dispatcher. The web server incorrectly allows access to any path containing '.cgi' without validating session cookies. Furthermore, the netis.cgi dispatcher invokes the firmware update handler without verifying the authentication state of the request. Because the firmware update process relies on a weak additive checksum and static product strings rather than cryptographic signature verification, an attacker can push unauthorized or malicious firmware to the device. This enables persistent, full control over the compromised router.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify the target Netis NC63 router and confirms the firmware version V3.0.0.3327.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a multipart POST request targeting the /cgi-bin/upload_fw.cgi endpoint.\u003c/li\u003e\n\u003cli\u003eThe request is sent to the target device without a valid session cookie.\u003c/li\u003e\n\u003cli\u003eThe Boa web server processes the request, bypassing authentication checks due to the '.cgi' extension.\u003c/li\u003e\n\u003cli\u003eThe netis.cgi CGI dispatcher accepts the request and passes it to the internal firmware update handler.\u003c/li\u003e\n\u003cli\u003eThe firmware update handler verifies the forged additive checksum and static strings, failing to perform cryptographic signature validation.\u003c/li\u003e\n\u003cli\u003eThe router processes and writes the malicious firmware image to flash memory.\u003c/li\u003e\n\u003cli\u003eUpon reboot, the malicious firmware executes, granting the attacker persistent administrative control over the router.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the permanent compromise of the Netis NC63 router. As a network edge device, a compromised router can be used to facilitate man-in-the-middle attacks, intercept traffic, exfiltrate sensitive data, or serve as a persistent foothold for lateral movement into the local area network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately restrict administrative access to the router web interface to trusted management IPs only.\u003c/li\u003e\n\u003cli\u003eDisable remote management on all internet-facing interfaces.\u003c/li\u003e\n\u003cli\u003eMonitor network logs for multipart POST requests directed at /cgi-bin/upload_fw.cgi.\u003c/li\u003e\n\u003cli\u003eCheck the Netis official support portal for firmware patches addressing CVE-2026-73673 and update all affected devices.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T14:13:46Z","date_published":"2026-08-14T14:13:46Z","id":"https://feed.craftedsignal.io/briefs/2026-08-netis-firmware-vulnerability/","summary":"An unauthenticated firmware update vulnerability in Netis NC63 routers allows attackers to bypass authentication and upload malicious firmware via the /cgi-bin/upload_fw.cgi endpoint.","title":"Unauthenticated Firmware Update Vulnerability in Netis NC63 Routers","url":"https://feed.craftedsignal.io/briefs/2026-08-netis-firmware-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - NC63 (V3.0.0.3327)","version":"https://jsonfeed.org/version/1.1"}