{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/nc63/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NC63"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","network-device","buffer-overflow"],"_cs_type":"advisory","_cs_vendors":["Netis"],"content_html":"\u003cp\u003eNetis NC63 firmware versions through V3.0.0.3327 contain a high-severity stack-based buffer overflow vulnerability, identified as CVE-2026-76070. The flaw resides within the login handler of the \u003ccode\u003e/bin/netis.cgi\u003c/code\u003e binary, which utilizes a custom Base64 decoding implementation. Due to the absence of proper length validation during the decoding process, an attacker can supply an oversized Base64-encoded password string to trigger a memory corruption event.\u003c/p\u003e\n\u003cp\u003eThe overflow occurs on a fixed-size stack buffer, enabling the attacker to overwrite the saved stack state and control the program execution flow. Because the underlying Boa web server operates with root privileges, this exploit results in full system compromise. This vulnerability is significant due to the lack of authentication required to reach the vulnerable code path and the resulting elevated execution context, posing a critical risk to affected network devices.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to gain root-level access to the affected Netis NC63 routers. This enables full device control, potential persistent access, lateral movement within the local network, and interception of sensitive traffic traversing the gateway.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade Netis NC63 firmware to a version beyond V3.0.0.3327 if a patch is provided by the vendor.\u003c/li\u003e\n\u003cli\u003eIf patching is not immediately feasible, restrict access to the web management interface of the Netis NC63 to trusted IP addresses only, using firewall rules.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic directed toward the web management port (typically 80 or 443) for unusually large or malformed strings sent to \u003ccode\u003enetis.cgi\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T18:03:00Z","date_published":"2026-08-24T18:03:00Z","id":"https://feed.craftedsignal.io/briefs/2026-08-netis-buffer-overflow/","summary":"A stack-based buffer overflow in the Netis NC63 login handler allows unauthenticated remote attackers to achieve root-level code execution.","title":"Remote Code Execution in Netis NC63 Firmware via Buffer Overflow","url":"https://feed.craftedsignal.io/briefs/2026-08-netis-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - NC63","version":"https://jsonfeed.org/version/1.1"}