What is CVE-2026-73673?
This CVE describes an unauthenticated firmware update vulnerability in Netis NC63 router firmware version V3.0.0.3327. Attackers can exploit a missing authentication check in the Boa web server and netis.cgi dispatcher to submit unsigned firmware images without any credentials. Applying the vendor-supplied security patch immediately is strongly recommended.
Azərbaycanca: Bu CVE Netis NC63 router qurğusunun firmware versiyasında autentifikasiya olmadan firmware yeniləmə zəifliyini təsvir edir. Təcavüzkarlar Boa web serveri və netis.cgi dispetçerindəki autentifikasiya çatışmazlığından istifadə edərək imzasız firmware şəkillərini yükləyə bilərlər. Mümkün qədər tez istehsalçı tərəfindən təqdim edilən təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Which components in the Netis NC63 router are affected by the authentication bypass in CVE-2026-73673?
The vulnerability stems from a missing authentication check in the Boa web server and the netis.cgi dispatcher.
What can an attacker achieve by exploiting CVE-2026-73673?
Attackers can submit unsigned firmware images without any credentials.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.