CVE-2026-76070 is a stack-based buffer overflow in Netis NC63 firmware through version V3.0.0.3327. The flaw is present in the login handling logic within the CGI component exposed by the device web interface, where an oversized Base64-encoded password is processed by a custom Base64 decoder without proper validation of decoded output length before copying into a fixed-size stack buffer. This allows an unauthenticated remote attacker to overwrite saved stack state. Because the affected CGI is executed by the Boa web server with root privileges, successful exploitation can result in remote code execution as root.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a research and proof-of-concept package for CVE-2026-76070, an unauthenticated pre-authentication stack buffer overflow in the Netis NC63 router web management interface. The vulnerability exists in /bin/netis.cgi, specifically the login handler for POST /cgi-bin/login.cgi, where the attacker-controlled password parameter is Base64-decoded into a fixed 64-byte stack buffer without any destination-capacity check. The repository documents that the saved MIPS return address is 136 bytes from the start of the decoded buffer, enabling return-address overwrite and program-counter control. Repository structure is small and focused: README.md provides the full vulnerability narrative, exploitation conditions, stack layout, dynamic validation results, and remediation guidance; attachments/decompiled-functions/ contains normalized decompiled C and disassembly excerpts for the vulnerable login handler and custom Base64 decoder; attachments/production-boa-config.txt captures original firmware web-server configuration showing root execution context and CGI paths; evidence/ contains hashes and runtime traces proving crash, PC control, and a guarded observation-only system() boundary test; and poc/poc.py is the only executable exploit code. The PoC script is intentionally limited and safety-scoped. It builds a form-urlencoded POST body where password is Base64 for a repeated 'B' pattern, defaulting to 140 decoded bytes. In dry-run mode it only prints the request body and metadata. With --send and an explicit target URL, it sends a POST request to /cgi-bin/login.cgi using urllib. The script does not contain a return-oriented chain, shellcode, command payload, persistence, or callback logic. Its main exploit capability is demonstrating the overflow and likely crashing the CGI process, while the documentation separately establishes that a private withheld chain reached the binary's existing system() call with attacker-controlled argument, indicating an RCE primitive in the vulnerable code path. Overall, this is a legitimate exploit repository centered on a public-safe PoC plus strong reverse-engineering evidence. It targets a web/network attack surface, requires no authentication, and is best classified as a POC rather than weaponized exploit code because the public implementation stops at crash/PC-control demonstration.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.