CVE-CVE-2026-73673
Severity
HIGH
CVSS Score
8.8
Description
Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsigned firmware images by exploiting a missing authentication enforcement flaw in the Boa web server and netis.cgi CGI dispatcher. Attackers can send a multipart POST request to /cgi-bin/upload_fw.cgi without a valid session cookie, bypassing authentication because Boa grants access to any path containing '.cgi' regardless of cookie validation, and ne...
PoCs for CVE-CVE-2026-73673
CVE-2026-73673
General
Shell
0
ozcanpng
2026-08-13