Unauthenticated Firmware Update Vulnerability in Netis NC63 Router
CVE-2026-73673

8.7HIGH

Key Information:

Vendor
CVE Published:
14 August 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-73673?

The Netis NC63 router firmware version 3.0.0.3327 has a significant vulnerability that allows attackers to initiate an unauthorized firmware update due to inadequate authentication checks in the web server. This security flaw enables malicious users to upload unsigned firmware images without requiring a valid session. By exploiting the weaknesses in the Boa web server and the netis.cgi CGI dispatcher, attackers can bypass necessary security measures and execute unauthorized commands. This vulnerability is particularly concerning as it relies on a forgeable additive checksum for validation, which does not ensure the integrity and authenticity of the firmware, leading to potential long-term compromises of the device.

Affected Version(s)

Netis NC63 Wireless AC1200 Router 0

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Özcan Ersan (@ozcanpng)
.