{"apiVersion":"1.0","identifier":"CVE-2026-76071","description":"Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verified, achieving remote code execution as root due to the Boa web server executing the CGI environment with root privileges.","publishedAt":"2026-08-24T16:17:23","lastModifiedAt":"2026-08-26T19:17:04","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-76071","cvssScore":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.01061,"riskScore":1.07,"affectedProduct":"Netis NC63","affectedVersions":"<=V3.0.0.3327","vulnerabilityType":"Firmware","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-76071","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-76071","en":"https://www.redsauce.net/en/cves/CVE-2026-76071","fr":"https://www.redsauce.net/fr/cves/CVE-2026-76071","pt":"https://www.redsauce.net/pt/cves/CVE-2026-76071","de":"https://www.redsauce.net/de/cves/CVE-2026-76071","sk":"https://www.redsauce.net/sk/cves/CVE-2026-76071","el":"https://www.redsauce.net/el/cves/CVE-2026-76071"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-76071"}}