CVE-2026-76860
moderateStack Buffer Overflow in Netcore NR255-V Router wake_up_set.cgi
Netcore NR255-V router firmware version 1.5.130703 contains a stack-based buffer overflow (CWE-121) in the wake_up_set.cgi endpoint, caused by unbounded tokenization of the MAC and ID parameters. An attacker with low-privilege access to the device's web management interface can submit crafted MAC and ID values that overflow a fixed-size stack buffer and corrupt program memory. Successful exploitation can yield full compromise of the router's confidentiality, integrity, and availability, most plausibly remote code execution under the device's privileged web/CGI process, enabling traffic interception or pivoting into the internal network. This firmware build dates to 2013 (version string 1.5.130703), so affected units are likely long-deployed, unpatched small-business/VPN routers primarily in Netcore's China market. No public proof-of-concept or confirmed in-the-wild exploitation has been reported to date.
What to do: Check with Netcore for a fixed firmware release for the NR255-V, as 1.5.130703 is the only confirmed affected version and no patched build is documented in the advisory. In the interim, restrict the router's web management interface to trusted LAN segments or a management VPN, disable remote/WAN-side administration, and enforce strong non-default credentials since exploitation requires low-privilege authentication. Monitor device logs for unexpected requests to wake_up_set.cgi and consider replacing end-of-life units that cannot be patched.
| Netcore NR255-V | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input. Attackers can supply crafted MAC and ID values to the affected endpoint to overflow the stack buffer and corrupt program memory.
- Weakness
- CWE-121
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.