ZeroHour

CVE-2026-76860

moderate

Stack Buffer Overflow in Netcore NR255-V Router wake_up_set.cgi

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Netcore NR255-V router firmware version 1.5.130703 contains a stack-based buffer overflow (CWE-121) in the wake_up_set.cgi endpoint, caused by unbounded tokenization of the MAC and ID parameters. An attacker with low-privilege access to the device's web management interface can submit crafted MAC and ID values that overflow a fixed-size stack buffer and corrupt program memory. Successful exploitation can yield full compromise of the router's confidentiality, integrity, and availability, most plausibly remote code execution under the device's privileged web/CGI process, enabling traffic interception or pivoting into the internal network. This firmware build dates to 2013 (version string 1.5.130703), so affected units are likely long-deployed, unpatched small-business/VPN routers primarily in Netcore's China market. No public proof-of-concept or confirmed in-the-wild exploitation has been reported to date.

What to do: Check with Netcore for a fixed firmware release for the NR255-V, as 1.5.130703 is the only confirmed affected version and no patched build is documented in the advisory. In the interim, restrict the router's web management interface to trusted LAN segments or a management VPN, disable remote/WAN-side administration, and enforce strong non-default credentials since exploitation requires low-privilege authentication. Monitor device logs for unexpected requests to wake_up_set.cgi and consider replacing end-of-life units that cannot be patched.

Affected
Netcore NR255-V
Estimated exposure
moderate≈ low thousands of internet-exposed NR255-V units (order-of-magnitude estimate; model-specific scan counts not published) — Netcore SOHO/enterprise routers sold mainly in the China market appear in internet-wide scan data at roughly tens-of-thousands scale across all models, and this specific VPN-router model with 2013-era firmware likely accounts for a small…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokenization of MAC and ID input. Attackers can supply crafted MAC and ID values to the affected endpoint to overflow the stack buffer and corrupt program memory.

Weakness
CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.