CVE-2026-73673
Received Received - Intake

Unauthenticated Firmware Update in Netis NC63 Router

Vulnerability report for CVE-2026-73673, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-14

Last updated on: 2026-08-14

Assigner: VulnCheck

Description

Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/upload_fw.cgi without a valid session cookie, bypassing authentication because Boa grants access to any path containing '.cgi' regardless of cookie validation, and netis.cgi reads but does not enforce the authentication state before invoking the firmware update handler, which accepts images validated only by a forgeable additive checksum and static product strings rather than a cryptographic signature, potentially enabling persistent router compromise.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-14
Last Modified
2026-08-14
Generated
2026-08-14
AI Q&A
2026-08-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
netis nc63 3.0.0.3327
netis nc63 to 3.0.0.3327 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-73673 is an unauthenticated firmware update vulnerability in Netis NC63 router firmware V3.0.0.3327. Attackers can exploit a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher to upload unsigned firmware images without a valid session cookie. The Boa server grants access to any path containing '.cgi' regardless of authentication, and netis.cgi fails to enforce authentication before invoking the firmware update handler. The firmware update process uses only a forgeable checksum and static product strings for validation instead of cryptographic signatures.

Detection Guidance

Check if your Netis NC63 router is running firmware version V3.0.0.3327 or earlier. Test for unauthenticated access by sending a crafted POST request to /cgi-bin/upload_fw.cgi without a session cookie. Monitor network traffic for unexpected firmware update attempts to this endpoint.

Impact Analysis

This vulnerability allows attackers to compromise the router persistently by uploading malicious firmware. This could lead to traffic interception, credential theft, or device bricking. Attackers can gain full control over the router's functions and network traffic, potentially exposing sensitive data or disrupting network operations.

Compliance Impact

This vulnerability could lead to unauthorized firmware modifications, enabling persistent compromise of network devices. Such breaches may result in unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's security controls for protected health information.

Mitigation Strategies

Immediately update the Netis NC63 router firmware to the latest version if available. Disable remote management features if enabled. Block external access to the /cgi-bin/upload_fw.cgi endpoint at the network perimeter. Monitor for unauthorized firmware update attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-73673. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart