Impact
The vulnerability is a stack‑based buffer overflow located in the destHost parameter handling of the ipFilterList=mod action in the netis.cgi script. An unauthenticated attacker can send an oversized destHost value via an HTTP request. The overflow corrupts saved stack state before authentication is validated, enabling the attacker to execute arbitrary code. Because the Boa web server runs the CGI environment with root privileges, successful exploitation results in full administrative control of the device.
Affected Systems
Affected devices are Netis NC63 routers running firmware versions V3.0.0.3327 or earlier. The vulnerability has been documented for the NC63 product line and is specific to the Netis Systems NC63 firmware. No other vendors or product versions are reported to be impacted.
Risk and Exploitability
The CVSS base score of 9.3 indicates a critical impact. The EPSS score is 1%, indicating a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog at this time. The attack vector is an unauthenticated HTTP request to netis.cgi, which is universally reachable from any network that can contact the device, making the risk high until the firmware is updated.
OpenCVE Enrichment