<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>NC63 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/nc63/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 24 Aug 2026 18:03:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/nc63/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution in Netis NC63 Firmware via Buffer Overflow</title><link>https://feed.craftedsignal.io/briefs/2026-08-netis-buffer-overflow/</link><pubDate>Mon, 24 Aug 2026 18:03:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-netis-buffer-overflow/</guid><description>A stack-based buffer overflow in the Netis NC63 login handler allows unauthenticated remote attackers to achieve root-level code execution.</description><content:encoded><![CDATA[<p>Netis NC63 firmware versions through V3.0.0.3327 contain a high-severity stack-based buffer overflow vulnerability, identified as CVE-2026-76070. The flaw resides within the login handler of the <code>/bin/netis.cgi</code> binary, which utilizes a custom Base64 decoding implementation. Due to the absence of proper length validation during the decoding process, an attacker can supply an oversized Base64-encoded password string to trigger a memory corruption event.</p>
<p>The overflow occurs on a fixed-size stack buffer, enabling the attacker to overwrite the saved stack state and control the program execution flow. Because the underlying Boa web server operates with root privileges, this exploit results in full system compromise. This vulnerability is significant due to the lack of authentication required to reach the vulnerable code path and the resulting elevated execution context, posing a critical risk to affected network devices.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to gain root-level access to the affected Netis NC63 routers. This enables full device control, potential persistent access, lateral movement within the local network, and interception of sensitive traffic traversing the gateway.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Immediately upgrade Netis NC63 firmware to a version beyond V3.0.0.3327 if a patch is provided by the vendor.</li>
<li>If patching is not immediately feasible, restrict access to the web management interface of the Netis NC63 to trusted IP addresses only, using firewall rules.</li>
<li>Monitor network traffic directed toward the web management port (typically 80 or 443) for unusually large or malformed strings sent to <code>netis.cgi</code>.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>network-device</category><category>buffer-overflow</category></item></channel></rss>