ZeroHour

CVE-2026-76861

niche

Stack Buffer Overflow in Netcore NR255-V Router CGI Enables Code Execution

CVSS 4.0
8.7 high
EPSS
Published
()
Modified
AI analysis

Netcore NR255-V router firmware 1.5.130703 contains a stack-based buffer overflow (CWE-121) in the ntools_tcpdump_start_set.cgi endpoint, caused by an unsized sprintf call that copies attacker-supplied form values into a fixed-size stack buffer. A remote attacker with low privileges — meaning anyone able to reach and authenticate to the web management interface, including via weak or default credentials common on these devices — can submit crafted form input to overflow the buffer and potentially execute arbitrary code on the router. Successful exploitation gives full control of the device (high impact to confidentiality, integrity, and availability), enabling traffic interception, manipulation, or use as a pivot into the network behind it. The flaw is rated 8.7 (high) under CVSS 4.0 and affects NR255-V units running firmware 1.5.130703, a build apparently dated 2013, suggesting the product line is legacy. No public PoC and no known in-the-wild exploitation have been reported, and the CVE is not on CISA's KEV list.

What to do: Inventory for any Netcore NR255-V units running firmware 1.5.130703 and immediately restrict the web management interface to a trusted internal VLAN or VPN — never WAN-facing — since the vulnerable CGI endpoint is reachable through it. Contact Netcore for patched firmware or plan replacement of this end-of-life hardware; in the interim, change any default credentials and watch for crashes, reboots, or unexpected tcpdump activity on the device. Block untrusted sources from reaching management ports (e.g., HTTP/HTTPS on the router) at the perimeter.

Affected
Netcore NR255-V1.5.130703
Estimated exposure
nichelikely on the order of low thousands of internet-exposed devices at most (clearly an estimate; no exact counts available) — The NR255-V is a discontinued Netcore SMB/VPN router deployed mainly in China and parts of Asia, and legacy Netcore models of this class typically show only low-thousands exposure in public internet scans; no model-specific scan data was…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an unsized sprintf call when processing form values. An attacker can submit crafted input to this cgi endpoint to overflow the stack buffer and potentially execute arbitrary code.

Weakness
CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.