CVE-2026-73673 is an unauthenticated firmware update vulnerability affecting Netis NC63 Wireless AC1200 Router firmware up to and including V3.0.0.3327. The flaw is caused by missing authentication enforcement in the Boa web server and the netis.cgi CGI dispatcher. A remote attacker on the adjacent network can submit a multipart firmware upload request to the firmware update endpoint without a valid authenticated session because access control is not properly enforced before the firmware update handler is invoked. The firmware validation logic further relies on a forgeable additive checksum and static product identifiers rather than a cryptographic signature, allowing attacker-supplied firmware images to be accepted. Successful exploitation can result in installation of malicious firmware and persistent compromise of the device.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused proof-of-concept and evidence package for CVE-2026-73673 affecting the Netis NC63 Wireless AC1200 Router firmware NC63_V3.0.0.3327. It is not part of a larger exploit framework. The repo contains 12 files total, with 2 Bash code files under poc/ and supporting documentation and runtime evidence under docs/ and evidence/. The main entry points are poc/make-probe.sh, which generates a 30-byte non-bootable firmware-like blob, and poc/request.sh, which submits that blob via curl as multipart/form-data to the unauthenticated firmware upload endpoint. The exploit capability demonstrated is unauthorized access to the privileged firmware update path over HTTP. The PoC targets POST /cgi-bin/upload_fw.cgi and uploads the crafted file in the update form field. According to the included documentation and traces, the request passes through Boa to /bin/netis.cgi, which reads /tmp/boa_auth but does not enforce authentication before dispatching to the firmware validation path. Validation appears to accept a minimal container with a cr6c header, checksum-compatible bytes, and the product tag NC63/NETISVC, after which the updater invokes /bin/fwd. The included trace shows the updater progressing to open("/dev/mtdblock0", O_RDWR), which is the flash-write boundary; in the isolated runtime this fails because no MTD device exists, preventing destructive behavior. This is a real exploit PoC rather than a detection script, but it is intentionally non-destructive and limited in payload capability. It does not deliver a shell or arbitrary command execution payload. Instead, it proves the missing authentication boundary and insufficient firmware authenticity checks by eliciting a successful HTTP response (["SUCCESS"]) and showing updater execution in trace evidence. The request script includes a safety guard that refuses non-local targets unless ALLOW_NONLOCAL=1 is explicitly set, reinforcing that the intended use is against an isolated local runtime such as the documented default target http://127.0.0.1:28081/cgi-bin/upload_fw.cgi.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.