Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 24 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi. Attackers can exploit the custom Base64 decoder's lack of output length validation against the fixed-size stack buffer to achieve remote code execution with root privileges, as the Boa web server executes the CGI environment as root. | |
| Title | Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password Parameter | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-24T18:28:13.077Z
Reserved: 2026-08-18T21:04:48.503Z
Link: CVE-2026-76070
Updated: 2026-08-24T18:28:08.289Z
Status : Received
Published: 2026-08-24T16:17:22.963
Modified: 2026-08-24T19:16:58.433
Link: CVE-2026-76070
No data.
OpenCVE Enrichment
Updated: 2026-08-24T18:00:04Z