PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-73673 Netis Systems Co., Ltd. CVE debrief

CVE-2026-73673 is a high-severity vulnerability in the Netis NC63 router firmware V3.0.0.3327, allowing unauthenticated attackers to submit unsigned firmware images due to a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. This vulnerability has a CVSS score of 8.7 and is considered high severity. The vulnerability allows attackers to bypass authentication mechanisms, potentially enabling persistent router compromise and disrupting network operations. Defenders should prioritize verifying firmware update authenticity and preventing exploitation.

Vendor
Netis Systems Co., Ltd.
Product
Netis NC63 Wireless AC1200 Router
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-14
Original CVE updated
2026-09-24
Advisory published
2026-08-14
Advisory updated
2026-09-24

Who should care

Defenders responsible for managing and securing Netis NC63 routers should be aware of this vulnerability and take immediate action to verify the authenticity of firmware updates and prevent exploitation.

Why it matters

CVE-2026-73673 is a high-severity vulnerability in Netis NC63 router firmware that allows unauthenticated firmware updates, potentially enabling persistent router compromise. Defenders should prioritize verifying firmware update authenticity and preventing exploitation.

  • Potential persistent router compromise
  • Unauthenticated firmware updates
  • Bypass of authentication mechanisms
  • Possible disruption of network operations

Technical summary

The Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. The vulnerability has a CVSS score of 8.7 and is considered high severity. The Boa web server grants access to any path containing '.cgi' regardless of cookie validation, and netis.cgi reads but does not enforce the authentication state before invoking the firmware update handler. The firmware update handler accepts images validated only by a forgeable additive checksum and static product strings rather than a cryptographic signature.

Defensive priority

Defenders should prioritize verifying the authenticity of firmware updates and ensuring that only authorized and signed firmware images can be uploaded to the router.

Recommended defensive actions

  • Verify the authenticity of firmware updates
  • Ensure only authorized and signed firmware images can be uploaded to the router
  • Monitor for suspicious firmware update attempts
  • Implement additional security controls to prevent exploitation
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The vulnerability was discovered by Ozcanpng and reported to the CVE Program. The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and vector. The source reference provides additional information on the vulnerability. However, the exact scope of affected systems and potential impact on network operations is not explicitly stated. Defenders should verify the authenticity of firmware updates and ensure that only authorized and signed firmware images can be uploaded to the router. The CVE Program, N

Sources and references

Verified primary and authoritative sources

  • CVE-2026-73673 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-73673

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-73673 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-73673

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.